■ Limit VLANs to a single closet when possible to provide the most deterministic and highly available topology. ■ Use RPVST + if STP is required. It provides the best convergence. My only thought is replace the SVIs on the core switch with VRFs, then do ACLs between the VRFs. Never attempted that before, so not sure if it is possible or practical. I do have budget constraints, so am hoping to accomplish this. In this issue, let's take a look at the six ways of VLAN division: 1. Basic knowledge of VLAN The Chinese name of VLAN is “Virtual Local Area Network”, not “VPN” (Virtual Private Network). VLAN is a new data exchange technology that logically divides LAN devices (note, not physically) into network. The following sections describe best practices for each of the three layers of the hierarchical architecture: access, distribution, and core. This technique enhances the performance, security, and manageability of ITS Networks by minimizing broadcast traffic, isolating diverse traffic and users, and simplifying troubleshooting. Trunking allows traffic from different VLANs on a switch to traverse the same link to another switch while at the same time, providing a method to segment the different user groups. Overview If you don't have access to a Cisco Modeling Labs server, you can reserve and use a DevNet Cisco Modeling. Maybe Private VLAN is what you're looking for: Private VLAN - Wikipedia I've never set that up so I'm unsure of the details or support on various firewalls.