Sorry to resurrect this but I am also facing a similar but more complicated problem.
I have many physical locations (about 20, each with a layer 3 switch, most connected to each other by ptp microwave links) but very few physical users (100 people).
I am using vlans and a meraki mx80 gateway providing dhcp for each vlan.
For security and virus/worm reasons I need to segregate a few vlans so that they can't see any of the rest of the network (the staff camp wifi) and go directly to the internet but I do want the work vlans to be traversable.
Currently the vlans are all using 10.0.x.x.
If I move the camp vlans to 10.1.x.x can use similar nomenclature as above to prohibit traversal?
Also some of my l3 switches (mainly Cisco 3560 series) do have IP routing turned on which I believe will negate this, I assume that I need to turn that off?