Thank you Derelict for the response.
This is what I am Planning now.
In each floor,
3 X Engenius EAP300 running on same SSID connected to unmanaged switch.
4 X Network Printers connected to same unmanaged switch.
The unmanaged switch from each floor is connected to 28 port Cisco SG300 Managed switch. The ports are protected so there is no communication between floors. This will prevent users from one floor sending Print command to Printer connected to another floor.
The SG300 Cisco is connected to Pfsense Box #1 which will have the following settings :
1) LAN IP 192.168.4.1/22 ( since I have ~ 400 users)
2) DHCP server
3) Common Captive Portal
4) Freeradius to keep a check on each users monthly quota of Internet Usage.
5) A simple proxy ( Squid + Squidguard) to prevent access to unwanted sites.
The Pfsense Box #1 is connected to a Load Balancer (PFsense Box #2).
So now there are no VLAns. ( The VLANs things were getting too complicated as it is Coworking environment with ~50-60 teams of different sizes, not feasible to provide that).
Are there any flaws in this setup. Is there something that I should take care.
Thank you all for your support. The reason I love Pfsense is the support I get from you all.
Regards,
Ashima