In first case, where I move the SSA management on the 172.29/16 networks, I've got a switch that has one NIC (the one that receive the mirror traffic) on the internal LAN and the management NIC on the demo LAB, and I know that in this case is secure, but for our policy I need to pass from the internal firewall (someone has fair that if an hacker corrupt the switch can pass between the two networks without pass thought the firewall). Regardin add a second NIC to the purview engine, I can't because I've tried to do this, but I've got networks with different masks and the wizard on purview engine want that I use the same masks on all the interfaces...probally I need to configure this scenario in manual mode...