Not sure if I can really go into the specifics here (in part because I am not really across them, my brief is getting the office firewalls working).
But in the general case you might have a mismatch between the performance, scaling, service levels, operational requirements, etc. required for the office and what's required for the services on those hosts, and putting a host behind a server running PF isn't necessarily a significantly more secure set-up than running PF on the host itself.
But in the general case you might have a mismatch between the performance, scaling, service levels, operational requirements, etc. required for the office and what's required for the services on those hosts, and putting a host behind a server running PF isn't necessarily a significantly more secure set-up than running PF on the host itself.
"