I quite often find that for a number of reasons, it's much easier to use NAT for faux-internal networks (ie: a VPS with multiple jails but only 1 public IP), and for remote access VPNs. Especially remote access VPNs...
However I almost always end up getting things wrong, and I'm not sure why...