Large DMZ Security Designs ?

I’m looking for references to “best practices” for large DMZ designs incorporating both functionality and security. Is segmentation based on port traffic the best approach or something else. All responses appreciated.
Thanks,
T