Hi Mustafa
It is never a good design to have 4000 ACE in a single ACL. So I guess there are really two options:
1. Modify the ACL to have lower entries use wild card masks to reduce the size of the ACL. I mean its not like that the customer has such a dis-contiguous network that you cannot club entries together. By the way, why such a peculiar requirement ?
2. Like you said, create multiple vlans.
But I would recommend option 1.