@podilarius:
Well, to me if the real purpose is to use the 2.x network, then I would drop the 85.x network. Setup the WAN ip you use in pfSense to also allow a VPN, so that you can connect a VPN and RDP to any host.
Then setup NAT or routing/firewall to pin hole the traffic you want to pass. You could keep the second as a failover, but that would be only for outbound traffic.
It might be possible to do what you want with just the 2 networks.
thanks for your reply, after a bit of work i tried your suggestion but it started getitng messy, and totally lost where i was and what i was trying to do..
instead now i wanna just keep it simple i.e. :
1 pfsense 2.0 vm with 2 NIC (1 getting DHCP ip from a network with internet access 10.170.85.x ) and (another on a network {private} that requires static IP 10.170.2.x)
i think it would be easier for me to config it so that pfsense appliance accepts pptp and ipsec connections from Internet wan (10.170.85.x) and then forwards the connection to the private Lan's wan (10.170.2.x)
kindly please guide me in this, and many thanks for your initial idea.
regards