tuaris, a mix dns would be a PIA, but fruitful…however, i am running internal DNS with reflection/NAT on many websites, mail servers, etc. i have yet to run into a problem with RC3.
i only allow dns through my dmz and all is grand. reverse lookups havent had a problem.
ofcourse i have more than one static (200+ statics at the moment) ...but i still havent run into a problem you might be worrying aboot.
also, the hardware i am running is prehistoric compared to the hosting environment..and it runs like a top.
i replaced TWO paloalto 5500's with pfSense (not load balanced, but failover setup) ...and not only do i have LESS work to do compared to the paloalto's ...i have better performance on VPN, email, and www. ...so...i was a skeptic at first, but i have quickly become a big ol fan of pfSense.