We have a large infra setup, and we are using pf firewall rules for controlling which server communicates with which server. Now when we are going to migrate the DB (just an example), we would like to retain the private IP, so that we dont have to change the of firewall rules, or the connection endpoints in the code.