I think the issue also applies to a single organization with multiple services.
For example, I might have a public website that should be accessible worldwide, while an ownCloud instance should only be accessible, for example, from Germany. If they use different public IPs, I can apply different firewall policies to those IPs.
So for me, the main issue isn't really multi-tenancy, but having different security policies for different services.
At the moment, I actually only have two web servers where different policies apply, so I tried the workaround with DNAT rules and separate ports for these. So far, this seems to work quite well. Thanks for that!
For example, I might have a public website that should be accessible worldwide, while an ownCloud instance should only be accessible, for example, from Germany. If they use different public IPs, I can apply different firewall policies to those IPs.
So for me, the main issue isn't really multi-tenancy, but having different security policies for different services.
At the moment, I actually only have two web servers where different policies apply, so I tried the workaround with DNAT rules and separate ports for these. So far, this seems to work quite well. Thanks for that!
"