I have a VLAN for cameras and my main network can talk to it, but the Camera VLAN cannot initiate any traffic out. Right now, it is only wifi Nest cameras, but I will transfer it over to PoE and wifi UniFi cameras. I have thought about someone ripping down a camera and plugging into my home network. I figured the Camera VLAN is a decent solution since once everything is set up, they will only be able to get to other cameras and that's it.
I have done some configuring of the VLANs and zone based firewalls and port manager. For all the switches in my house, if a port is not is use, I set it up to only use the Default network. I have the ZBF set up so that with the Default network, the device can get an IP address but that's it. All other access is blocked. It is isolated as possible. This works great from a security perspective, but is a PITA when I have to plug something into a blank port on a switch, I forget to update the settings, and then I get frustrated trying to figure out why it isn't working for about 10 minutes.