I always create a "Deny All" rule for my entire local subnet. This blocks all inter-vlan traffic. All inter-vlan traffic that I want to permit I put above that line, and everything else goes below it. In your case, you would put the ICMP rule above the Deny All rule. Here is an example:
... View more