I am not trying to start a flame war with you guys. The diagram can work, but also can be better very simply by doing the things I have outlined. I never said don't learn something new. Most people on the board are learning something new. When you need to patch a router it does not take down the other services. When the time comes to patch the LMCE you may break something else to secure the box. The dependencies in Linux may make it so a simple patch can cause 3-4 additional patches that could break something in the LMCE. Placing the LMCE at the network edge means everything must traverse it to get to the internet. Lets say I was playing an online game and somebody else was streaming a movie. This brings a potential quality of service issue that could be easily avoided with a different design. The latency added in this scenario that could possibly be bypassed with a longer cable run directly to the router. My arguement isn't just it makes it easier. It makes it more secure, reliable and expandable. Let's say the earlier scenario comes to light where we are expierencing congestion. If we use the LMCE as the router/FW we cannot segment the networks easily and quickly resolve a QOS issue. Under what I am saying you merely would add a cable run and use the 2nd nic in the LMCE. Peng good luck on your install and I hope this banter has helped some =)