@stephenw10:
@Arisian:
The great thing about Christmas, is that my wife apparently still wants the internet to work today. Pssh…
Ha! I feel your pain. ;D
What _JT has described above should work but it's not how I would do it or many other people here on the forum.
Having your R7000 NATing between the 10.0.0.0 and 11.11.11.0 subnets is a bad idea. You're just making far more work for yourself, increasing the possibility of errors by many times. You should have one internal subnet and allow all the devices on it to be handed and IP by the pfSense DHCP server. You can probably turn of routing and NAT of the R7000 using DD-WRT (it's been a while since I used it) in which case you can use all 5 ports and you'll see no reduction in throughput.
You shouldn't be using 11.11.11.0 at all because that is not a private subnet! If you ever need to access a server at 11.X it won't work.
Steve
I understand what you mean…if the server of the TS is not sufficient to handle both firewalling, NATting and traffic then it might be best to buy a new router. Just built one myself with an Athlon 5350, works great :)