I do have VLANs. And It does seems to make sense to use GP for them and keep the main Network rules small and clear. As I think thru this, my biggest fear is managing the different VLAN rule sets and repeating between them. I feel like managing multiple rules sets might be hard. The first thing that comes to mind is building a tool to compare rules between the Group Polices to make sure that I have added or removed from all policies as appropriate. Does something like this already exist?
... View more