For security reasons, Is it possible to connect all Entrypoint via Subdomain only?

Question asked by EddieBuckmeier on Jul 17, 2015
For Security Reasons we are protecting our system with an deny,allow over htaccess, so only our office-IP is allowed to connect to the Sugar-Server. But certainly we want still use our entryPoints, with trackbacks, Web2Lead etc. Is there any known possibilty or Idea how to channel all the requests for the entrypoints through a subdomain, and from there to the main Server?

The Idea is a controlled access of a second IP (Subdomain) to our Sugar-System.
