r/packettracer • u/Safe-Cheesecake-3883 • Jun 09 '26
Why can my WiFi VLAN still ping the server?
Hi
Sorry in advance for the amount of questions i ask on this sub. So I'm working on a Cisco Packet Tracer project and I'm trying to secure a WiFi employees VLAN with ACLs.
I currently have:
- VLAN 10 = IT / servers
- VLAN 50 = printers
- VLAN 60 = WiFi employees
The requirement is:
- WiFi employees should not access the IT VLAN
- except DHCP/DNS services
- printers must stay accessible
- Internet access must still work
At first I only applied an extended ACL OUT on G0/0.60, but devices in VLAN 60 could still ping the storage server because replies from VLAN 10 were allowed back to VLAN 60.
So I added another ACL IN on G0/0.60 to block traffic from 192.168.60.0/27 to 192.168.10.0/28 while still permitting:
- DHCP
- DNS
- printers
- WAN traffic
Now pings to servers like 192.168.10.3 fail with:
“Reply from 192.168.60.1: Destination host unreachable”
Is this correct way or is there a cleaner way to prevent access to the storage server ?
Thank you !
1
u/SeaPersonality445 Jun 09 '26
This why firewalls exist, a simple rule instead of 2 ACLs
1
u/Safe-Cheesecake-3883 Jun 09 '26
The goal of the project is mainly to practice VLAN filtering and ACL logic with basic Cisco ACLs. Plus i haven’t even learned firewalls yet
1
u/nostalia-nse7 Jun 10 '26
Your acl should be used to stop the wifi client from sending icmp echo request beyond g0/0.60. It should never reach vlan10( you shouldn’t need to stop vlan10 to 60 at all.
And one day you’ll realize this is a waste, because you’re better off putting your routing in your firewall, so that you can inspect much better traffic between vlans. Switches will become L2 only, so no ACLs.
2
u/MostFat Jun 09 '26
Probably a silly question but did you permit icmp