Hi ar,
For the EXOS switches in a DMZ, personally i'd suggest not having an accessible switch IP on the DMZ-facing data plane side of things. Keep management of this switch only via the separated management port using SSH, SNMPv3, disabling telnet, disabling web browsing, which can be plugged to a completely separate (internal) iLO-type switch (not VLAN 1) so this traffic does not touch the DMZ-production traffic whatsoever. That way you'll have eyes and ears on the switch but not risking the switch itself.
Different issue with the EOS switches though, obviously they've not got a mgmt port. Whilst you may have firewall rules in place, locked down for say SSH, SNMPv3, no telnet or web browsing etc, to this switch management, longer term i'd look to swap them out for the purple EXOS switches to keep the management and DMZ-production separate and to avoid punching holes in your Firewall for switch access.
Hope this helps?
Thanks
Rob