Well it WAS all going to plan............
I created an extended ACL;
permit ip 10.15.0.0 0.0.255.255 10.11.0.0 0.0.255.255
permit ip 10.15.0.0 0.0.255.255 10.12.0.0 0.0.255.255
permit ip 10.15.0.0 0.0.255.255 10.217.0.0 0.0.255.255
permit ip 10.16.0.0 0.0.255.255 10.11.0.0 0.0.255.255
permit ip 10.16.0.0 0.0.255.255 10.217.0.0 0.0.255.255
permit ip 10.14.0.0 0.0.255.255 10.11.0.0 0.0.255.255
permit ip 10.14.0.0 0.0.255.255 10.12.0.0 0.0.255.255
permit ip 10.14.0.0 0.0.255.255 10.217.0.0 0.0.255.255
permit ip 10.13.0.0 0.0.255.255 10.11.0.0 0.0.255.255
permit ip 10.13.0.0 0.0.255.255 10.127.0.0 0.0.255.255
permit ip 10.217.0.0 0.0.255.255 10.217.0.0 0.0.255.255
It worked initially - I set a workstation on 10.16.0.10 pinging both 10.14.0.10 and 10.217.28.12 - I applied the ACL to the port, and communication to 10.14.0.10 was blocked, whilst 10.217.28.12 carried on
But - 15-20 seconds later, I got a "Limited or no connectivity" notice (WinXP) and everything stopped. Even DHCP has stopped (DHCP server is 10.217.28.12).
I turned the rule off - applied it again, and got the exact same thing.
I tried again - This time a fresh PC - I applied the rule, plugged in the PC, and don't even get dhcp.
I'm assuming I've blocked DHCP somehow..........