If you are fine with slow performance communication between a few specific end systems in each of the VLANs, you can use a firewall to route and filter between them. A switch is designed to allow line rate forwarding between end systems, and can do some filtering as well. A firewall is designed to filter traffic, and do some forwarding as well.