2. hosts in the vlan can ping inside the vlan (switch has IP, replies), but they can‘t ping the firewall, can’t connect to the firewall and can’t communicate through the firewall (neither ping nor higher services).