I wonder if it's safe to place Virtualmin or Cloudmin directly on the front edge without any firewall in front of it. Virtualmin looks very secured with the default IPTABLES firewall and optional plug-ins (denyhost, etc.). I am just double checking.
I would rather not placing anything else in front of it to avoid speed and performance bottle neck by additional layer(s) of firewall(s). However, if necessary... would you recommend having either 1 edge and 1 application firewall in front of Virtualmin or Cloudmin? Example:
Internet --> Edge FW (Pfsense, Cisco, OpenBSD, etc.) --> Virtualmin/Cloudmin.
Internet --> Edge FW (Pfsense, Cisco, OpenBSD, etc.) --> Microsoft TMG (Threat Management Gateway) --> Virtualmin/Cloudmin.
Thank you in advance for your help.