Can I get your opinion/pointers on the following scenario? I’m sure both ways work, but which is best?
Corp VLAN 10
Guest VLAN 50
Both have SVI's on 2960 switch, but only for troublshooting/mgt purposes. Gateway IPs are on router.
There is a router on a stick config on 1941 router - g0/0.10 and g0/0.50 and that's where the two networks meet.
What is the best way to block traffic between the two networks? VACL on the switch? ACL on the router?