I just re-read your configuration, seems you currently have different subnet on VLAN1... Actually, I don't have tried as your configuration, if you want to make it standard, you can consider my setting above. If you just want to minimal the downtime, you can assign two ports on the layer 3 switch as a router port by "no switchport" command, then one is for those internal lan ip address, another one is for WAN. I think it will works too, but not recommend.