So I am a volunteer for a small non-profit (social club), and although not a network engineer, I a somewhat advanced home user (SSL VPN's, QOS, etc., on my home network.
Here's my initial thoughts, but I am probably missing something.
|-Primary WAN
|-Backup WAN
...>VLAN POS (wired clients...