That is quite a big question.
Enable layer 3 routing on your MS350. Create a VLAN201 on the MS350. Put an IP address on it in the same subnet as your firewall. Put a port into access mode, assign it to VLAN201, and plug your firewall into it. Add a static default route to your firewall IP address.
Your firewall will also need routes for all subnets no the MS350 via the VLAN201 IP address on the MS350.
All ports that will machine machines attached should be put into access mode.
You can change the native VLAN on any port that is going to be a trunk port. From the sound of your configuration, there wont be any need for trunk ports.
Each VLAN should have an IP address on it.
You might find it much easier to just have a single VLAN and put everything on it.