Thank you for the answer, I am however curious, seeing that we have a number of VLAN's, what is the solution to block this kind of behaviour on all of them? So effectively have a mechanism that when a new VLAN is created, we can simply create a single rule as appose to updating each interface?