A flat network is simple, but often gives every connected device more reach than it needs. Segmentation can separate management, guests, servers, cameras and IoT, provided routing and firewall rules are designed deliberately.
VLANs are only a mechanism. Without suitable rules, two VLANs may still communicate fully, or critical services may be blocked unintentionally.
In more complex environments it is useful to draw the intended traffic on paper before configuring switches and firewalls.
A VLAN separates broadcast domains at layer 2. A router or firewall determines which traffic is allowed between those networks. Segmentation without policy rules is therefore not automatically security.
That depends on risk and function. Guest devices, cameras, IoT, management interfaces and servers are common candidates. Do not create more segments than you can understand and maintain; complexity can become a risk in itself.
Plan a management path and test rules step by step. Keep local console or recovery access available for critical equipment. Document trunk ports, tagged and untagged VLANs, addresses and routing rules before making changes.
Yes, but both protocols need their own addressing and firewall policy. A secure IPv4 design does not automatically mean IPv6 follows the same policy. Check both paths explicitly.
Practical network investigation fits Digital.