Installing a new network and have decided on the hardware that will be used.. Next up is to start planning the best configuration settings I should use.
If you were presented this hardware diagram how would you suggest the network config be done? Ip addressing, Subnetting, Vlan setup, DHCP server location, etc???
I will need to setup some internet bandwidth shaping features so that the “Production” VLAN always get priority in regards to upload and download internet bandwidth. I think this will be done in the Mikrotec.
Is there a way to make it so that the “NetworkAdmin” Vlan can see and talk to every device on the network in every vlan? All the other Vlan’s don’t need to be able to communicate to each other.
I haven’t done the research yet, but I am assuming there is a way to assign openvpn tunnels to certain Vlan ID’s? So when I configure a remote phone using open vpn, that tunnel will be placed in the PBX vlan? Also, if I needed to remote into the network, I could setup up an openvpn tunnel that is assigned to the “NetworkAdmin” vlan?

Datasheets for the hardware.
Router = Mikrotik hEX S RB760iGS
https://mikrotik.com/product/hex_s#fndtn-specifications
Layer 3 Switch = Cisco Business CBS350-24P-4X
https://www.cisco.com/c/en/us/products/collateral/switches/business-350-series-managed-switches/datasheet-c78-744156.html
Smart Switch = Cisco Business CBS250-8P-E2G
https://www.cisco.com/c/en/us/products/collateral/switches/business-250-series-smart-switches/nb-06-bus250-smart-switch-ds-cte-en.html
Access Point = Cisco Business 240AC
https://www.cisco.com/c/en/us/products/collateral/wireless/business-200-series-access-points/smb-01-bus-240ac-ap-ds-cte-en.html
Access Point = Cisco Business 145AC
https://www.cisco.com/c/en/us/products/collateral/wireless/business-100-series-access-points/smb-01-bus-145ac-ap-ds-cte-en.html
UPDATE…
So here is what I am am thinking about using for the Ip Class, Subnetting, & Vlans
10.12.0.0/18
CIDR IP Range 10.12.0.0 - 10.12.63.255
Subnet Mask 255.255.192.0
10.12.10.0/24, SM 255.255.255.0, Range 10.12.10.0 - 10.12.10.255, VLAN10, Network Devices
10.12.11.0/24, SM 255.255.255.0, Range 10.12.11.0 - 10.12.11.255, VLAN11, NetworkAdmin
10.12.12.0/24, SM 255.255.255.0, Range 10.12.12.0 - 10.12.12.255, VLAN12, PBX
10.12.13.0/24, SM 255.255.255.0, Range 10.12.13.0 - 10.12.13.255, VLAN13, Production
10.12.14.0/24, SM 255.255.255.0, Range 10.12.14.0 - 10.12.14.255, VLAN14, Office
10.12.15.0/24, SM 255.255.255.0, Range 10.12.15.0 - 10.12.15.255, VLAN15, Classroom
10.12.16.0/22, SM 255.255.252.0, Range 10.12.16.0 - 10.12.19.255, VLAN16, Guest
10.12.20.0/22, SM 255.255.252.0, Range 10.12.20.0 - 10.12.23.255, VLAN20, Event