Once you are working with VLAN's you are out of the bailiwick of consumer hardware, and you should be looking at more enterprise grade gear.
At that point having a default drop on the external interface and different rules for traffic traversing VLAN's is entirely possible, in fact that is what it is designed and built to do.