Hi Patrick, Le 05/09/2013 05:24, patrick keshishian a écrit : > > Does there exist a nice way to do this without further sub-dividing > the /28? >
I would bridge the Internet-facing interface and the interface that connects to the switch. This way you can filter with PF without subnetting your /28. Denis