I'd like to disable management access to wans for the internet as a whole, but Id still like to be able to have our Ops/Engineering team be able to manage the device without needing to VPN in from home, is this doable?
Yes, as long as you know the IP's they would be coming from -Configure this in the access list, for that interface.
