Seconding Peter's request that you not top-post. We read and write this language left to right, top to bottom, and nothing about email changes that.

You say "un-trusted devices" but would have to trust the device to configure a VLAN interface. Or back to the ProCurve, it would need to be configured to tunnel everything on a the untrusted port into a VLAN. And/Or configure so that the untrusted port is switched only to the FreeBSD router port.

Would be easiest to slip another NIC in the FreeBSD router for this purpose. Then no VLAN, everything is handled in your firewall.

