This may be a dumb question, but is there any need/benefit to using Switch ACLs instead of or in addition to Layer 3 FW rules? The Layer 3 rules seem much simpler to configure and maintain. Is this primarily meant to be used for in deployments without an MX or are there use cases for using ACLs along with Layer 3 FW rules?
Agree, we only use switch ACLs to stop VLANs from talking to each other, that is if it's a L3.
Otherwise do it all at the firewall to reduce complexity.