Segmentation is a policy problem
A firewall does more than block internet traffic. In a segmented environment it becomes the policy point between trusted and less-trusted network zones.
The useful question is not simply whether two VLANs can route to each other. It is whether the business has a reason for that communication and what controls should apply to it.
Build policies around intent
Define the source, destination, service and business purpose for each important rule. Keep administrative access separate from ordinary user traffic where practical.
A smaller set of understandable policies is easier to review than a large collection of exceptions created over time.
Treat change as part of security
Firewall configuration should be documented and reviewed as the environment evolves. Backups, controlled changes and clear ownership are just as important as the initial policy design.