And while I'm pretty adepts at networking as I wrote router code in the 90's I still didn't get what you needed to do.

I think you need to task your IT team to deal with this. It might require better gear like managed switches that only allow this or that.