Couldn't you run two separate firewall's, three NIC's each. Use opt1 on each FW as a sort of bridge between networks? sdsl-----m0n0wall(1)----DMZ | | | cable----m0n0wall(2)----LAN - Don