The rules do not work on real hardware. That is, traffic goes counter not see that the ACL is triggered. Moreover, in the emulator, PT. all works without problems.
The question that can affect which rules do not work? or maybe I do not understand something.
A piece of iron Catalyst 3750X
Most of what is included in the Config. If you need something even more in the config skins.
ip address 192.168.1.4 255.255.255.240
ip access-group NET1_in in
ip address 192.168.1.18 255.255.255.240
ip access-group NET2_in inip access-list extended NET1_in
permit ip 192.168.1.0 0.0.0.15 192.168.1.0 0.0.0.15
permit ip 192.168.1.0 192.168.1.16 0.0.0.15 0.0.0.15
ip access-list extended NET2_in
permit ip 192.168.1.16 192.168.1.16 0.0.0.15 0.0.0.15
192.168.1.16 0.0.0.15 permit ip 192.168.1.0 0.0.0.15
When you ping from 192.168.1.1 to 192.168.1.17 icmp pass but the counter shows that it works. similarly, from 192.168.1.1 to 192.168.1.17