If the workstations are only going to be used for web & mail, you might
consider giving them RFC1918 addresses and force them to use a proxy server
located on the external NT box. This would eliminate the ability for people
on the 'net to connect to your workstations, and you would only have to
maintain one point of exposure.
Kevin C. Miller Custom Software Design & Network Consulting
CEO, FreshWater, Inc. kevin@devworld.com