hello, its easy to do that.
this configuration permit any communication from vlan 1 to 2, but visa versa is deny.
just copy these and paste it as it is.
ip access-list extended VLAN_2
Permit ip 192.168.8.0/21 any
Permit TCP any 192.168.8.0/21 established
Permit ICMP any 192.168.8.0/21 echo-reply
Deny ICMP any any echo
Deny TCP any any eq telnet
Permit ip any any
VLAN 2
ip access-group VLAN_2 VLAN
ip access-group VLAN_2 in
Regards,
A.S