vlans are to separate broadcast traffic, and they do ..
if you want traffic to go from one vlan to an other you will have to have routing at some point.
in extreme "enable ipforwarding" is just turning on Routing between vlans
if you want security, you can use an ACL