Additional tips:
-If you use VLAN1, put its IP configuration under switch 0 vif 1 , not under switch0. Assign firewall rules under vif 1 , and nat rules on switch0.1
-While playing around with the switch configuration, leave a single port out of the switch. On this port put a management IP for time being so you can still access the device if something goes wrong with switch config.
If switch works as intended, final step is to place the last eth port under the switch