Hi everyone,
I have an incoming internet connection with 16 ip addresses I can use. Previously I had this going directly into one router, but I've decided to set up another independent LAN for several of the ips. Since I only have one incoming connection, I plan on using a portion of a CRS317 switch to break it out to 3 separate ports.
I want to use sfp ports 1-4 for breaking out the WAN connection, and ports 5-16 for the LAN side. As such I put each of those two sets of ports on their own bridge. The switches dhcp has been set to use the LAN side. Eventually the LAN side will be configured with the various needed VLANs.
My questions are as follows:
1. Is this the right approach?
2. Is it secure? What concerns me is that winbox still sees the switch even on the WAN connection, even though I have the winbox service disabled. I hope I can set this up without firewall rules.
3. Can this run at wire speed, or will setting up securely disable hardware acceleration?
Basic configuration is attached.