Well I assume there is a reason you put an interface between the servers...
The below applies to all fire-walled traffic.
Be very mindful of what traffic is allowed, and even that should be limited as much as possible to keep your window of opportunity as small as possible.