Here is the list of current limitations for Inter Vlan feature (http://wiki.cloudstack.org/display/PM/Inter-VLAN+Routing):
* All networks inside the VPC should belong to the same account * Only VR and Netscaler are supported as LB providers. For all other services support only VR as a provider in Burbank. * LB service can be supported only by one tier (network) inside the VPC * Firewall rules support through Network ACLs only * No remote access VPN support * Supported hypervisors. Beta release - VmWare only; GA - VmWare, Xen, KVM * No public gateway exposure to the end user, therefore no Static Routes support for the public gateway * Private gateway can be created by the ROOT admin only for the end user VPC * No routes blacklist (he can do firewall rules on his side of physical network devices) * Public Ip address can't be used by more than one Guest network at a time inside the VPC. If you have network1/network2 and public IP1, you can create PF rule for either IP/network1 or IP/network2, but never for both. -Alena.