So, I have a dilemma. I'd like to move by main firewall to a separate building away from where my WAN comes in but I only have a single ethernet cable linking the two buildings.
I currently run a VLAN trunk between the buildings using the new Bridge VLAN filtering method. The WAN comes in to an area where noise is an issue so don't want to run a new CCR there but the other building is not a problem for noise.
The top diagram is the current setup and the bottom is an example of what I'm looking for:-
Ideally the WAN would come in to the HAP AC at port 1, this would somehow be passed though to the CCR in building 2 where the WAN interface will be, all firewall rules, DHCP server, DNS etc will be on the CCR. The LAN's and VLAN's will also be setup on here and the VLAN's/LAN's will also pass back to the HAP AC in building 1 where LAN clients will also be. Clients exist in building 1 and 2 across all VLAN's as well as Wireless devices in different VLAN's in both buildings.
Question 1: Is this a safe and sensible thing to do? My gut instinct is that it's not a great Idea but if some way a the WAN can be securely transported across the same physical cable as the LAN VLANS then could it be ok?
Question 2: How best could this be achieved. I'd like to keep the bridge vlan filtering setup if possible for the LAN side. One possible way I thought of would be to set up bridge VLAN filtering as normal, create an extra VLAN for the WAN as normal and then somehow pass EOIP over that VLAN to create the link.
Any ideas would be appreciated. Hope this all makes sense.