@cmb:
What I recommend is only bridging OPT interfaces, as then the bridged interface doesn't need an IP.
I was thinking about that, but then LAN and WAN would be my manage / pfsync interfaces, which would be confusing name wise.
@cmb:
That's deceiving, it's actually broken in FreeBSD 6.x and greatly reduces throughput. http://pfsense.blogspot.com/2007/06/polling-and-freebsd.html
I read this link before I enabled it and the idea seemed sound: http://taosecurity.blogspot.com/2006/09/freebsd-device-polling.html .
@cmb:
That should never be necessary for any purpose, hence there is no supported facility for making manual ruleset changes.
True, it shouldnt be needed, just thinking that it would be nice to have just in case