Hi Brian,
If 10.1.20.10 can reach 10.1.30.1, then the AP has a gateway to reach any other network and that is 10.1.20.1. Similarly, are you able to reach 10.1.20.1 from 10.1.30.100? If not, please check if the default gateway is configured. Trunking is not necessary to the link connecting to the firewall as switch is acting as Layer 3. However, each host in the network should know how to reach other subnets with default gateway pointing to the switch VLAN IP address.
Hope this helps!
P.S. If these hosts are windows PCs, just check if the ping is allowed by the firewall..