Ok, first off - thanks for thinking with me.
This is what I would like to accomplish. I have two physical GBit interfaces, one WAN and one LAN. I could add another two LAN card (or two el-cheapo USB3.0 ones, my network is not that demanding)
I could then map these physical interfaces to pfSense interfaces, and have DHCP work on each one. Even though connected to the same switch, I could still 'sort' the DHCP traffic that way by using static mapping to the correct network. It would be less physically secure than the VLAN route but should thwart most of my children's evil plans (they do not do network design ;-) )
[image: Network.png]
[image: Network.png]
[image: Network.png_thumb]