In terms of a starting point, assuming ether1 is your WAN connection, then I would take ether 2 out of the bridge and configure it with it's own IP address, subnet, DHCP (if required) etc. This would make ether1 your WAN, ether2 your DMZ and the other ports would be bridged together into your insid...