Well moving the permit tcp any any established below the deny ip any 10.0.0.0 0.255.255.255 wouldn't allow reply traffic(established tcp) if you wanted to rdp into the guest vlan from another vlan in 10.0.0.0 0.255.255.255.I'm also seeing similar iss...