Discuss your findings. Is it better to make strict ACLs and let users ask for exceptions, or to use few ACLs and only add them as they are discovered to be needed? What are arguments for both approaches?
How different is a firewall from a router capable of ACLs, NAT and PAT to control traffic flow?