one other note. if you plan to use templates for the branch/spoke sites the firewall rules can use objects that reference the underlying site specific subnets. per your example, the template firewall rules could use objects for workstations, phones, printers, guest, and vendor. dashboard works out that those objects actually refer to site unique subnets underneath like 10.201.x.x, 10.202.x.x, etc. templates aren't right for everyone as they only allow a certain amount of variability. when you have sites that are very similar templates can be great. you'll need to evaluate if it works for your deployment.
... View more