@Ambarishrh said:
Is it a good practice to have a firewall first between internet and WFE servers and then between WFE and Application Servers? I am looking for a design diagram for such a setup
Depends on your needs. For a small setup, probably unnecessary. For compliance, potentially required.
We use firewalls against every single device on our network at the VM level. Communication in and out is always monitored and we have procedures on allowing traffic through. This provides compliance and proper lockdown between machines.
Don't think of the firewall as another device. If you have a single device, additional subnets with it inspecting the traffic is sufficient.