Is it ideal and secure to assign a public IP address to one of the jails which serves as a PF firewall and router while assigning a local IP address to the host? I am thinking of a topology as in the attached diagram where the physical server will be on a CF card with / in read-only mode, and the rest of the jails will be mounted on a zfs pool.
Any inputs (including about the proposed topology) from the FreeBSD/NanoBSD experts are welcome and appreciated! Thanks!
PS: I understand that it seems like a single point of failure, but that would be addressed using a HA system in a different system as well as in a different location.
Any inputs (including about the proposed topology) from the FreeBSD/NanoBSD experts are welcome and appreciated! Thanks!
PS: I understand that it seems like a single point of failure, but that would be addressed using a HA system in a different system as well as in a different location.