Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer applies an IPv6 ACL to filter traffic…

An engineer applies an IPv6 ACL to filter traffic between two VLANs on a switch using a router-on-a-stick configuration. The ACL is applied inbound on the subinterface. Traffic from VLAN 10 to VLAN 20 is permitted, but return traffic from VLAN 20 to VLAN 10 is dropped. Which is the most likely explanation?

⚠ Common exam trap

Cisco often tests the misconception that an ACL applied inbound on one subinterface controls all traffic between VLANs, when in fact it only filters traffic entering that specific subinterface, and return traffic must be permitted by an ACL on the opposite subinterface or by an outbound ACL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ACL on the VLAN 20 subinterface is missing a permit entry for the return traffic, or the ACL is applied outbound on VLAN 10, which does not affect incoming return traffic.

In a router-on-a-stick configuration, traffic from VLAN 10 to VLAN 20 is permitted by the inbound ACL on the VLAN 10 subinterface. However, return traffic from VLAN 20 to VLAN 10 must traverse the VLAN 20 subinterface inbound (or the VLAN 10 subinterface outbound). If the ACL is applied inbound only on the VLAN 10 subinterface, return traffic from VLAN 20 is not inspected unless an ACL is also applied inbound on the VLAN 20 subinterface or outbound on the VLAN 10 subinterface. The most likely cause is that the ACL on the VLAN 20 subinterface is missing a permit entry for the return traffic, or the ACL is applied outbound on VLAN 10, which does not affect incoming return traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ACL is applied only on the VLAN 10 subinterface, so return traffic from VLAN 20 is not filtered but the ACL on VLAN 10 drops it because the source address matches a deny entry.

    Why it's wrong here

    This is incorrect because return traffic sourced from VLAN 20 enters the router through the VLAN 20 subinterface, so an inbound IPv6 ACL on VLAN 10 never sees it. Even if the ACL's deny entry matched the source address, the router would not evaluate it for packets arriving on VLAN 20; only an outbound filter on VLAN 10 could affect that flow, and the issue is a missing permit, not a deny match on the wrong interface.

  • ✓

    The ACL on the VLAN 20 subinterface is missing a permit entry for the return traffic, or the ACL is applied outbound on VLAN 10, which does not affect incoming return traffic.

    Why this is correct

    This is correct: the failure is caused by asymmetric IPv6 ACL application. Forward traffic from VLAN 10 to VLAN 20 is permitted by the ACL on VLAN 10, but return traffic from VLAN 20 is either dropped by an inbound ACL on VLAN 20 that lacks a permit for that flow, or never checked because the only filter is outbound on VLAN 10, which cannot inspect the packet as it arrives on VLAN 20. To fix it, add an explicit permit for the return direction on the VLAN 20 inbound ACL or an outbound permit on VLAN 10.

  • ✗

    The router has 'ipv6 unicast-routing' disabled, preventing inter-VLAN routing.

    Why it's wrong here

    This is wrong because disabling 'ipv6 unicast-routing' globally stops the router from forwarding any IPv6 packet between subinterfaces, breaking all inter-VLAN communication, not just return traffic. The observed behavior—forward traffic succeeding and only return traffic failing—is a classic sign of a one-way ACL, not a missing routing enablement. Additionally, the router would not even build the IPv6 FIB for the subnets if unicast routing were off.

  • ✗

    The ACL uses 'deny ipv6 any any' which blocks all traffic, but the permit statement for VLAN 10 to VLAN 20 is placed after the deny, causing it to be ignored.

    Why it's wrong here

    This is wrong because IPv6 ACLs are processed sequentially with first-match semantics; a permit statement placed before the deny entry is evaluated first, so it is not ignored. If the ACL really ended with 'deny ipv6 any any' after a permit for VLAN 10 to VLAN 20, the forward traffic would be allowed and only unmatched return traffic would hit the deny. The actual problem is the absence of a permit for the return flow, not ordering—if ordering were as described, all traffic from VLAN 10 would be blocked too.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.