Thanks AP very much!
I understanded your ideas, the topology you have recommend is more secure.
due to your solution, all my app server was sit on internal netwwork and DMZ. Only one firewall VM was directly connected to internet, this pfsense will hanlde all trafic to these app server by port fowarding and NAT rules.