We use a Meraki MX as a Firewall appliance and have DMZ networks on it. Essentially create a separate VLAN for each DMZ and in the Firewall rules, deny all access from the DMZs to the Internal network and other DMZs. We then connected the MX to a core router that has another MX handling the SD-WAN VPN. This allows you to restrict DMZ access as @cmr said.
... View more