>You could also rehome the vlans to your firewall When the data flows are not high - this is my preferred approach. I like to do all my firewalling and access restrictions in one place. Switch ACLs can also be applied per-vlan - so you could consider moving these devices into their own VLAN. You can also simply specify the devices address in the source and destination field. If you have an MS Advanced licence, and a suitable switch, you could also consider using Adaptive Policy. You can apply a policy to a specify port this way, using an Adaptive Policy "tag". https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Adaptive_Policy_Overview
... View more