Non-3GPP access (untrusted Wi-Fi, wireline) must use N3IWF or TNGF with IKEv2 and IPsec for secure tunneling to the 5G core, with authentication anchored in 5G AKA.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.