@DannyZ
If you got the VLAN right but still cannot get INTERNET. I think it has something to do with your VLAN. How do you set the VLAN(to port) profile on your switch?
Do you just get a computer connected to the port and get a matching VLAN or?
So, since you mention IOT, it's more like WiFi AP. Right? For AP, you don't have to set anything or modify any ports on the switch. Instead, you just go and set up your WLAN and make that SSID match with the VLAN ID. Will this work for you? When I do my VLAN for WiFi, I don't set anything because the Omada can do a lot for you on its own. You just pay attention to the WLAN part.
If you intend to use a device(like a switch) to the Omada router/switch, you need to set the port profile on the switch. If you want to make it a trunk port, you set the profile to "All". If you want a dedicated VLAN for a specific port, you use a certain VLAN profile for the port.
There is no need to use any static routing. First, check your IP, do you get IPs from the VLAN 4 and 99? I think it's more like an issue with the VLAN interface instead of ACL.
PS
What is the version of your controller and ER7206? Are they up to date? I think you first need to make sure the configs are right before setting up the ACL.