@eg1995 Web app proxy (WAP) can work with or without ADFS. ADFS is not a requirement for WAP. If you just want to configure WAP to translate external URL to internal URL, you do not need to have ADFS in place. While publishing the exchange URL, you can use the same Go Daddy certificate that you have. You do not need to deploy a CA server for this purpose.
It is always a best practice to have WAP server in DMZ. A secure network topology with WAP looks like this:
Internet > Coroprate firewall (external) > WAP Server > Corporate firewall (Internal) > Backend server (in your case, Exchange)
In the above scenario, you can assign public IP address to external firewall and map the traffic for specific ports such as HTTP/HTTPS (80/443) to be forwarded to the WAP server.
Although a public IP address can be assigned directly to WAP server, it is not a best practice from security perspective. In such scenarios, you would need to keep internal firewall as restrictive as possible.
Hope this includes answer to all your q uestions.
-----------------------------------------------------------------------------------------------------------
Please "Accept as answer" wherever the information provided helps you to help others in the community.