Why don't you just put these users into two different vlans with different IP address ranges and use an access-list? I think that is the best solution, given that they are in different departments anyhow.
MAC access-lists are not a scalable solution, and on top of that, on some platforms may just not work at all. Depending on the platform, a MAC access list will *ONLY* match traffic that is not IP or IPv6 (appletalk, DECnet, IPX, etc. etc.)
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...