If you need to do traffic shaping and DHCP, you can't use a bridged setup. You'll need a routed public IP subnet for an internal interface, and like a /30 for your WAN, where your ISP routes your internal public subnet to your WAN IP. Then disable NAT (see FAQ) and you're set.
|