I would like to isolate our general networks from our AVL Networks.
Our AVL Networks are on another VLAN.
Devices on the AVL VLAN should be able to talk to each other, a few resources on the Default VLAN, and reach the internet.
What is the best way to isolate these clients from our other networks? Assigning VLANs to the Switches? Assigning Port Profiles to the Switch ports that have the right Native VLAN and allow only AVL VLAN? Using Group Policies?