The problem sounds like this: I need to create acl to block access from c to a, but allow access from a to c (full ip access, not just ping). And then i need to block access from D to a and c, but alow a and c access to b. Any ideas? The topology run...