You should put the router Mac address in 'DMZ Plus' mode if you want to avoid double-NAT issues.
'DMZ Plus' mode allows you to configure one device on the network share the public IP.
It's better to get a smart switch than finding a router that does 802.3ad LAG/LACP.
I run LACP on my Netgear GS108T "Smart" switch for both my Synology NAS & the Mac.
Damn.. Tried the basic $69 UAP which I really liked and was set to get AP-AC before finding about no ZH :(
Now the choices are:
- Airport Extreme Base Station
- Asus RT-AC87U
- Netgear R8000 X6
Vendor encryption claims (software or hardware) are usually for volume encryption (data-at-rest).
They usually don't benchmark data-in-flight secure connections because of possible network congestion factors.
Try Redhat Storage Server (GlusterFS AMIs) across two AZs.
This might be easier to manage (though I never tried it): SoftNAS VSA
https://www.youtube.com/watch?v=17lc7Qw4BgQ