Is this really works? the way i see it. you still permitted TCP traffic to flow both ways. from vlan 10 to vlan 20. and vlan 20 to vlan 10. Im having the same problem with my SG350 series. most switches uses "permit tcp any any -established-"in CLI. ...