-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Adam, > Or you assign the rule to the interface, rather than the address. > Nothing new, that is how firewalls work on DHCP clients today. that will be pretty difficult on the perimeter router ... Best regards, Peter. -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iEYEARECAAYFAk95eW0ACgkQ+8TW1Xhd1gcSXACg0Sculr5FUZ1yQxIHp581r0Gi musAnRUVVMVav2HBKmQuK6IDmVY98jrt =Fazc -----END PGP SIGNATURE-----