I wish to set up a number of networks on a single switch and perform routing and ACL enforcement between VLANs on the same switch, and between VLANs and external networks. What is the low end of the Cisco switch offerings that will allow me to create this architecture? The documentation for the Catalyst 3500XL doesn't addres intra-VLAN access control, so I assume something higher-end is required.