I currently have separate VLANs for faculty, staff, and students, with ACLs allowing access to different internal resources. We have a Catalyst 4507 as our L2/L3 core switch, and all our access switches are L2 only, with trunk ports to the core, and ...