I feel first option is good.
I agree. It makes the setup much cleaner and easier to troubleshoot. Just take care that you only allow HTTPs to the NAT IP from the outside.
I feel first option is good.
I agree. It makes the setup much cleaner and easier to troubleshoot. Just take care that you only allow HTTPs to the NAT IP from the outside.