@warloxian
1:
May i suggest you download the Free DIA diagram writer program
https://forum.netgate.com/topic/166945/free-network-diagram-drawing-tool-for-win-mac-or-linux
And make a drawing of your "As IS" and "To BE" network.
2:
Since this is a LAB , that will end up with multiple vlans (else it's not a lab)
I will suggest you assign a : 10.xx.yy.00/16 network to your lab network.
Then you would have room for 255 labs (xx) with 255 (yy) /24 networks (vlans) , that can be used in your lab(s).
Match the xx to your "Lab number" , and yy in the ip address to the same vlan number.
Ie. 10.xx.10.0/24 would also be vlan 10
Ie. 10.xx.20.0/24 would also be vlan 20
etc ...
Hint ... Do not use 10.00.x.x or 10.01.xx.xx
Aka avoid using "Lab 00" and "Lab 01"
Those ip's are way to used by ISP's , and will bite your behind at some time.
I'd start with "Lab 101" (10.101.xx.00/16) or something "random" you feel for
3:
If possible i'd prob use the USB as "Lab Wan" , as the built in adapter prob. has higher performance , and would be better used for the "Lab inside vlans"
I like to always have my WAN connected via a "Real L3 interface" , have seen too many "Vlan Leak bugs" on "Consumer switches" to trust a Vlan as my WAN.
4:
You would need a Vlan capable switch for your LAB inside, to "Fan out" the multi vlans to separate ports.
5:
I did a ultra brief intro on how2 make a vlan on a pfSense here
https://forum.netgate.com/topic/158196/making-best-use-of-physical-nics-vlans/6
Affordable switches
I like the D-Link DGS-1100-08v2 switches $42
https://www.amazon.com/D-Link-Ethernet-Managed-Internet-DGS-1100-08V2/dp/B08P2C2GXF/
They are basic vlan capable switches , for a nice price.
Basic means they can't do ie. 802.1x authentication , or SNMP write confguration.
But they can do (i think 32 Vlans) and IGMP etc ....
They're nice low wattage fanless "sattelite" switches ...
I also like the DGS-1210 series also fanless (they can do 802.1x auth etc ...)
But they seems to be in backorder , prob. due to the Chip shortage.
I use DGS-1210-24 and DGS-1210-28 , in EU you can get them for around $150 , if in stock.
I'm not sure if the TP-Link's have gotten their vlan leaks under control in the current revision, but they were NOT recommended a few years ago.
/Bingo