Yes, you are correct on VRFs only thing is if the VLANs have a common uplink ( which they usually do ) then you will have import/export routes between the VRFs and this can get a bit ugly/complicated for a switch ( in my opinion ). Firewall filters are a cleaner more appropriate solution and you can even apply them through JWEB, which makes it easier.
Just make sure not to apply them during operational hours and be careful when applying the filter to a vlan interface your accessing SSH on :P. Filters and direction of filter on interface leave room for many mistakes and errors.