Hi All, We're trying to lock down our remaining Windows XP machines to minimise our exposure to unsupported OS, and one thing we're considering is a dedicated VLAN with an ACL that allows only specific traffic through to specific servers (DNS, LDAP, ...