I guess it really depends on how you want to manage it.I use Virtual IP's and use specific Source and Destination NAT's to achieve the 1:1 NAT without publishing all services.