So I got the Managed Switch and now I have several VLANs:
VL10_MGMT
VL20_SEC - this is were main clients will connect (mostly via WIFI) and it'll use a VPN_WAN gateway.
VL30_CLR - sort of a DMZ where I connected all LAN devices (Freenas and its jails, Receiver, TV, AppleTV, etc)
VL40_GUEST - WIFI network only for... guests
VL50_IOT - where I'll connect several IoT devices via WIFI (smart lamps, dimmers, climate, etc)
Makes sense?