Hi,
We are planing an upgrade from v13 with an "old" and network rules focused firewall setting, to the new windows application based firewall in v14.
The problem for us, is that our rules are quite heavily based on normal acl priority based rules.
How do you guys handled the move to the new firewall way of thinking?
We stop all client to client traffic today, except for mgmt networks.
And that's an easy task with the >v14 firewall, but now.. not so much 
And that is beq I think in the "old" way 
Very simplified pseudorules below 
1. allow ip $MGMT network
2. allow ip $SRV network
3. allow ip $SPECIAL_CLIENTS (some small subnets on $CLIENT/16)
4. deny ip any $CLIENT network
This works if the rules are read as the old(normal) way 
But now everything must be so granular if we try to use our old thinking..
So any Ideas are welcome 
--
Regards Falk