@NogBadTheBad:
Also as John mentions most access-points need their management interfaces in an untagged vlan.
For most situations (such as UniFi) you can have everything tagged on the firewall and just set your ports native on the lan-vlan and tagged on the wifi-vlans. Only exception I have seen is some crappy switches that can only be managed from vlan 1. It is also sometimes needed when you don't have the luxury of re-programming the entire site. That being said, my early Cisco training stressed that it was bad practice to use vlan 1 as a production vlan, and I avoid it when possible. Your mileage and OCD may vary.