Hey, Sometime in the next couple months we're going to be replacing a large part of our infrastructure to increase the already excellent reliability (dual nics and psus everywhere, etc). I'm just speccing up some kit for quote, and I'm slightly undecided as to the best things I can do with the firewalls. At the moment I'm looking at NATting stuff to 3 different zones (private networks), and hopefully bridging to a 4th zone. It'll have 10 nics, all paired off into round-robin bonds, so 5 usuable interfaces. 1 colo facing, 3 private, 1 "public". Can you DNAT packets to IPs X, and Y, Z assigned to a bridge, while bridging those IPs not assigned to it? (There is probably going to be a small amount of firewalling on the bridged IPs) Thanks -- Mike Williams