Are the any requirements for keeping your deployment LAN separated from your Production LAN, like multicast filtering, security, etc?

Are the machines in your production LAN already able to interact with the Fog server for client updates, snap-ins, etc?