virtual ISP - Basis Setup- Firewalls

I am setting up a basic virtual ISP network; i.e., riding on a Host network.

For the Core Router, I selected the CCR1036-12G-4S router which i want to use as follows:

  1. As a firewall for the virtual ISP network ( i.e separating my network from the Host network)
  2. As a Firewall between end users ( my customers) , the Host network and My Network
  3. For routing traffic between my virtual network and the Host Network.

I also selected the CRS326-24G-2S+RM which i will use as access switches offering internet services to my customers over 1GE ports.

My projection is up to 1000 customers within 2 years.

I need to know from anyone with experience in this area for the following :
a. Do I need a physical Firewall to cater for Requirement (1) and (2) above?
b. What nature of problems, (if any) , can i face if i cascade ( CRS326-24G-2S+RM) switches ?
c. If i run IPTV services over such a network, are there any problems which am likely to face ?

Appreciating any comments from the forum

Regards