Thanks for clearing that out--since I asked I had a major network redo and had two major "aha!" moments and I'm back to only the edge firewall + L3 switch and using every feature Windows Server's DHCP server has. I've been offline for really long periods while I broke some stuff.
But I accomplished what I wanted and was told repeatedly not to do it: DHCP option 121.
0_1551518079822_Screen_Shot_2019-02-13_at_08_45_54.png
I really liked the simplicity of using a transit network because all rules lay on a single interface plus a few floating ones it's awesome--parting from that and from this diagram I found:
:
0_1551518599407_chilli.png
and... your confirmation about no NAT needed (I'm really grateful, BTW) I'm thinking about setting up a captive portal as a transit network and whitelist hosts as needed. My previous experience with portals was with the UniFi system--it never occurred to me to look at things from another perspective.
I'll keep breaking stuff a little more, it's weekend, see what else can I learn--thanks a million!