All labs
Guest, DMZ and internal flows
Allow only the necessary path. Public service in the middle; private data behind another boundary.
Public service in the middle; private data behind another controlled boundary. A VLAN label is not the whole policy.
Guest → internet HTTPS
Guest → staff file server SMB
Internet → reverse proxy in screened subnet
Internet → internal database
App in DMZ → database on a specific port