The firewall filters are applied to the routed vlan interfaces themselves so only need to be applied on the switch with these interfaces configured.
The downstream switches in your case have only one routed interface so they cannot cross vlans directly. They are using the interface on the core switch.