With the Sophos XG Firewall and the Cisco swithces, what model would you recommend I get?
Changing the password on the miners is definitely a good thing to do, but will not completely protect them. Don't sweat the static IP issue, I am using DHCP with reservations for the miners and it has been a very stable solution for me.
Regarding the firewall, I suggest a XG-210 appliance or get the software version is you have a spare computer or server that has at least 2 network interfaces on it. If you use your own hardware, you can use the Sophos "home" (software) version for free. The Sophos platform is very robust and supports many VPN configurations.
Just about any Cisco switch will do, since you are running in a datacenter, I would get one that you can rack mount. I suggest taking a look on ebay, there are lots of good, used Cisco switches there for $100-$200 - well worth the price. Get a late model. I have a WS-4948 and it works great. I know 48 ports is overkill, but it is a good switch and the price is right. If possible, get one with redundant power supplies.
If you need any help getting all this to work, PM me, I am a network engineer and specialize in network security. No charge to help out fellow miners
(Moderator's note: This post was edited by frodocooper to remove a nested quote.)