Pfsense behind AT&T router

I moved closer to family last year, and rented an apartment. My ISP is AT&T , with BGW320-505 router. Where I lived before I had (still have) a Netgate SG-2100 Pfsense router. When I moved I just plugged all my equipment (desktop, laptop, printer, NAS, and IOT devices into the AT&T router.

Everything runs fine, except the apartment complex replaced all the entry locks with Alarm.com Smart locks. While doing so they installed a ADC DC-NK-200T-A hub in my closet. Plugging its ethernet into my AT&T router, unplugging the ethernet cable to the living room for my TV. The new hub has a large label stating not tu unplug the power or the ethernet.

The AT&T router assigned the new hub an IP (192.168.1.***), just like all my existing devices on the network. Major security issue, the hub can see all my devices!!

What I would like to do, is resurrect the SG-2100 device, allow the AT&T router to assign the WAN port a 192.168.1.*** IP and have the SG-1200 LAN ports connected to my devices as a 10.*.*.*.* address. But the At&T router will still give the new hub a 192.168.1. IP. Set up the Pfsense firewall to block any queries from the hub 192.168.1* IP from connecting to the 10...* network. Allow the 10.* network to connect to the internet and still get the appropriate responses.

So the ISP router will only have the fiber WAN connetion, an LAN connection to the new hub, and a LAN connection to the SG-2100.

Is this possible?

Thanx, Rich

By default pfsense blocks devices on the WAN so having the AT&T device assign a 192.168.1.x address for the WAN is pfsense as well as the other devices is fine as it will still be blocked. For routing to work make sure you do not have the default pfsense 192.168.1.0/24 assigned to any interface.