We ran into the ACL limit years ago, and were told the switches could not handle more than 128 without becoming unstable. Will also add using ACLs compared to MX firewall rules is much more tedious, as you cannot group IPs and/or ports. Major pain in the butt. We ended up moving L3 back to MX, with the exception of some SQL and other server subnets. If I were starting fresh, I probably wouldn't use L3 switch for anything except maybe iSCSI or some other comparable protocol.
... View more