@fastcon68:
I do have the vlans setup up for 2 and 3.
I have the opt1 interface and the opt2 interface bridged to the lan subnet.
@fastcon68:
I really do want to isolate the two vlans away from the other network. I have machines that should only see the wan and nothing else.
Do not bridge them to Lan then (did you read the article about network bridging???)
Create pass rules for OPT1 to WAN only and similar for OPT2 to WAN.
@fastcon68:
I have setup the IPSEC rules as well, I can ping the out to the my sites but they can come back my way. that is cause issues for me. Any thoughts?
Huh, what do you mean?
Usually that's the desired behaviour to have a two way communication between IPSec endpoints.
…however, on the IPsec rules tab you can control what's allowed in and what's not.