Gabriel, Bringing up an old thread but im looking at something similar. Im interested in creating an Allow ACL with a global Deny at the bottom for any non-defined subnets. When i do this i lose inter-vlan traffic. As an exampleLooking over the synta...