I don't have access to the os of the servers connected to the switch, so a software firewall is not posible.
If I set up a vlan for each port I will be able to define both "in" and "out" acls (as far as I understand) but the servers connected to the switch also need to be able to communicate...