Ideally, AD DC and Keycloak external hosts should be on its own subnet, and each IPA deployment should also be on its own network.