I'm using pf, because all of my servers have one NIC on each, and all of my jails are using private IP addresses. The host gets a public IP, so pf does all the routing between the host and the jails. As for the database which also resides in a jail, I only open up the database port for the web...