I was actually wondering if I was being to 'jail prolific'.
Nah, I don't think so. With resources being so cheap now, I don't think running extra jails is really going to bog down your machine. I have 6 jails running and it doesn't even seem notice most of the time. I could be wrong though.
Where you suggest to turn on the firewall is that on the base install or per jail?
I'm not sure how you have your jails set up, but I put all of my on one of my NICs, NAT'ed together. I use PF as a firewall and route traffic as necessary. It's pretty easy to block all incoming ports and only allow certain ports to redirect their traffic to specific jails. Check out the handbook or the Networking forum for some examples. Regardless, PF will be enabled on the main OS and that should be the only thing you will have to manage.