expected OpenBSD use: Firewalls surprise: actually using pf always in pairs, in failover config carp, pfsync firewalls always have the policies on the vlan interfaces need to isolate customers from each other the router-facing interfaces only do some spoof protection