Management of all network devices is restricted to the management network MGMT, VLAN 99, IP 10.10.99.0/24.
There's a dedicated management port on the switch, i.e. an (untagged) assignment to VLAN 99 on core switch port 24.
In order to manage the FabLab network infrastructure from anywhere, an OpenVPN access is required. The OpenVPN client will get an IP within the subnet 10.10.23.0/24, which on the firewall is allowed to access all networks. Therefore, this VPN should be restricted to authorized admins only.