>If you are looking to isolate machines from each other it might be worth
>seeing if your switch supports private VLANs. The idea behind this is that
>devices on each port on the switch can only see the default gateway (the
>m0n0wall which sits on a promiscuous port that is seen by all the other
>ports in the VLAN), whilst at the same sharing the same subnet.
Good idea. This would be a much easier way to do this. I believe you are
referring to port-based VLANs as opposed to 802.1q VLANs. I have done this
in a test environment in my office with much success. This would allow
Jurgen to use one OPT on m0n0 and a single DHCP server.
Aaron |