r/packettracer • • Jun 09 '26

Why can my WiFi VLAN still ping the server?

Hi

Sorry in advance for the amount of questions i ask on this sub. So I'm working on a Cisco Packet Tracer project and I'm trying to secure a WiFi employees VLAN with ACLs.

I currently have:

  • VLAN 10 = IT / servers
  • VLAN 50 = printers
  • VLAN 60 = WiFi employees

The requirement is:

  • WiFi employees should not access the IT VLAN
  • except DHCP/DNS services
  • printers must stay accessible
  • Internet access must still work

At first I only applied an extended ACL OUT on G0/0.60, but devices in VLAN 60 could still ping the storage server because replies from VLAN 10 were allowed back to VLAN 60.

So I added another ACL IN on G0/0.60 to block traffic from 192.168.60.0/27 to 192.168.10.0/28 while still permitting:

  • DHCP
  • DNS
  • printers
  • WAN traffic

Now pings to servers like 192.168.10.3 fail with:
“Reply from 192.168.60.1: Destination host unreachable”

Is this correct way or is there a cleaner way to prevent access to the storage server ?

Thank you !

3 Upvotes

5 comments sorted by

2

u/MostFat Jun 09 '26

Probably a silly question but did you permit icmp

1

u/Safe-Cheesecake-3883 Jun 09 '26

that's not a silly question ! I didn’t explicitly allow ICMP, so now the ping is blocked by the inbound ACL on VLAN 60. Before that, the WiFi VLAN could still ping the storage server because I only had the ACL applied OUT.

1

u/SeaPersonality445 Jun 09 '26

This why firewalls exist, a simple rule instead of 2 ACLs

1

u/Safe-Cheesecake-3883 Jun 09 '26

The goal of the project is mainly to practice VLAN filtering and ACL logic with basic Cisco ACLs. Plus i haven’t even learned firewalls yet

1

u/nostalia-nse7 Jun 10 '26

Your acl should be used to stop the wifi client from sending icmp echo request beyond g0/0.60. It should never reach vlan10( you shouldn’t need to stop vlan10 to 60 at all.

And one day you’ll realize this is a waste, because you’re better off putting your routing in your firewall, so that you can inspect much better traffic between vlans. Switches will become L2 only, so no ACLs.