hi Jeff
if use only two procurve switch
I recomended you must make option 2
so
2-learning switch with one commad all mac address on port with port security
edgeswitch(config)# port-security 1-23 address-limit 1 learn-mode static action
send-disable
with this command all port learn dynamically each mac address on port and only one mac address permision and if connect any other mac address on port port turn disable status
very easy command
please test your 2610-24 switch
(config)# port-security 1-23 address-limit 1 learn-mode static action send-disable
switch learn dynamically at the moment connection mac address on port and this mac address sensible authorized mac address
if connect any other mac address on this port port is trun disable state
you must be turn port enable state with manuel command
(eth-13)# enable
in this way unauthorized pc unable connect your switch
important note:on uplink port (switch to switch ) don't port security config
your questions
yes it is possible
each port able sperate other port with
source port filter command
no need vlan
config)# filter source-port 1 drop 2-23
with this command port 1 between port 2 to 23 connection drop port 1 permit connection only interface 24 if you connect interface 24 internet router port 1 user only comminication internet router unable connection other pc