My Network:
Did have a Juniper SRX210 routing / firewalling but picked up a little MikroTik box to learn their OS with too (do seem to get a lot of features for the money).
Probably going to add a second AAISP Be line at the end of the summer and (should see around 40Mbit down and 5Mbit up when bonded).
3 VLANS:
10 = Phones, 6x Cisco 7940G's talking to my own Asterisk server running on a VPS.
20 = Wired Clients, A couple of PC's & a Mac Pro, Mini, printer and content server and a couple of dev boxes.
30 = WiFi Network for Phones, laptops, visitors etc.
No NAT in my network at all as its evil and pointless when I have a real ISP who are happy enough to give me blocks of public IP's
Phones live in their own /29, likewise wired and wireless have their own /28's did think about trading them in for a single /27...
Each VLAN also has a /64 IPv6 network taken from the /48 assigned to me and all devices are issued with an IPv6 addy if they support it.
There's a couple of VPN tunnels not shown (one goes to the Asterisk box and the other to work).