We have a VLAN for DAG replication, Recoverpoint (SQL Data), and right now SMTP Shadow replication is going over with the production traffic.
Should shadow replication be limited to the site? Should it go across the WAN? If so should it be on a separate VLAN?
Q1. Should shadow replication be limited to the site? Should it go across the WAN?
-> It depends on how your AD-Sites are configured, and what are the requirements for message routing. If you are going to consolidate all smtp traffic and send it out through one-site, then you can have shadow redundancy configured across WAN.
to quote the Technet article on Shadow Redundancy:
http://technet.microsoft.com/en-us/library/dd351027.aspx
Q2. If so should it be on a separate VLAN?
-> Ideally you would want to isolate your message-routing, so the answer is Yes.