"but I bring a few VLANs into it (for running virtual machines on different segments)"
That is a valid reason.. But what does that have to do with the OS wouldn't that be controlled at the VM software?
"There may be exceptional cases when it is needed to "hack" the firewall."
exceptional for sure - 25 some years in biz, and never had such a requirement. If you needed something to be on a specific vlan, you can just use a different device on that vlan other than your "management" pc