Q3, I'd personally move the real ip addresses back to the firewall and have address the local subnet vlan 102 from some private addresses. The routers would then have a static for the real addresses to the firewall, and have the firewall NAT them. Q4, A topology diagram won't hurt. I would say that you're probably ok with what you have planned.

