Simply by creating , for public servers, their own broadcast domain, not the same of the ‘private’ lan, eg by assigning different ip addresses to ETH02 and ETH00 and keep the ETH02 as DMZ, while ETH00 as private lan ….. but if you are happy with the bridge, and it works as expected, don’t worry about 😉