@tlum: …What I'm hearing is that pfSense can't create a default interface dedicated exclusively to untagged traffic... Where do we lose you when saying: EM0 is your default interface and handles all untagged traffic. EM0_VLANxyz rides on top of that, tagged. You don't need to create it, it's there when you assign a network to a (physical) interface.