Quick question and best approach to this. We use Cisco Catalyst 9200 as WAN switch with internal Management connection (on MGMT port of course lol). We plan to use ACL for external and internal SSH access only. Should we have two separate ACL (one for external access and another for internal VRF access) or just use one ACL for both and include "also VRF" on the vty SSH access-list configuration? What is everyone school of thought. Thanks.
Cat 9200 you need to advantage licese for VRF. depends on how your ACL looks like, if they are different interface, then you have one ACL which cover both sides. or 2 ACL also works.