506
First Router Designed Specifically For OpenWrt Released
(sfconservancy.org)
This is a most excellent place for technology news and articles.
The key there is the switch does most of the work in hardware, so you can have 1G going between all ports with no CPU usage, so the internal 1G port doesn't matter as much, and the hardware acceleration lets it efficiently handle routing across VLANs without involving much of the internal port. Those internal switches can usually handle VLANs and basic NAT nesrly entirely on its own.
With a single external 2.5G port you lose that because your traffic will have to go in the router and back out to the switch to cross VLANs, so it's basically a 1.25G link. And it needs to be a managed switch too since the router doesn't come with a built-in one anymore. Best you can do is software VLANs but the other device will need to also use the VLAN explicitly in that case, as there's no switch to give you untagged ports.
So you would have to pair this with a switch that not only does VLANs but also somehow does your NAT for you.