I think you are basically on the right track: Configure multiple VLANs on the MX, at least one for the legacy 192 network, one for the new 172 network. Or directly implement multiple different new VLANs for Servers, Users, Printers, IoT, Voice, and so on. Either assign the VLANs to two of the ports where you use your old and your new infrastructure, or use a Trunk for the connection to the switch and implement VLANs on the switch. If you are quite new to networking, I would hire a consultant to design you a new secure environment based on your needs.
... View more