Actually I had the exact same question. I am trying to give access to security teams to a site network, but only for the firewalls/MX appliances. From what I gathered here, it seems I would have to create two networks for each site - one with all the wireless, switching, IoT, etc. devices, and one with the firewall appliances. I know it works, because I accidentally did this with switches and APs in different networks with similar names. However this seems like alot of extra legwork. Is this something Meraki is looking into in the future? Is my understanding of the current capability correct?