My side there is a large park level network, has about 40 sets of layer 3 switching, routing, 5 star structure, now must carry on the internal and external network separation, access to information found that separation of internal and external network is basic to add network brake equipment, now have no this aspect of the budget, so I wonder can replace it with the ACL + vlan way,
Basic train of thought for each switch port is divided into two vlans, and to set up the ACL per switch vlan limit the network access to a network vlan, is that possible?