I guess what you could do if you want to avoid nat for the servers is to setup an interface pair of virtual wire. Like: int1: L3 outside (internet ip's /24) int2: L3 inside (private ip's, nated to outside ip's) int3: vwire1 int4: vwire1 And then get another switch for the outside so it will become switch <- two cables -> PAN <-> one cable to the private ip switch, one cable to the switch for the servers The downside is that this looks a bit "complex", the upside is that if you dont like PAN in front of the servers its easy to just move them like you have it today - no need to change ip addresses, gateways, routing etc...
... View more