In version 3.x and later, the ability to secure different Virtual Local Area Networks (VLANs) with bridge groups is introduced. The limit on this is eight bridge groups in single mode. In this example, a transparent firewall connects the same network on its inside and outside interfaces. Each pair of interfaces belongs to a bridge group, to which you must assign a management IP address. You can configure up to eight bridge groups on two interfaces each. Each bridge group connects to a separate network. Bridge group traffic is isolated from other bridge groups; traffic is not routed to another bridge group within the Firewall - modules (FWSM), and traffic must exit the FWSM before it is routed by an external router back to another bridge group in the FWSM.
Note: This feature can be used in Transparent mode as well as Routed firewall mode.
In order to secure hosts on different VLANs, refer to this configuration example: