I take it the watchguard that has 2 wan ports and is NAT capaple?? If yes then can that device do NAT on a single port only leaving the other port as purely firewalled??
If yes then you already have the 2nd "ethernet router" as it's built into the watchguard