If i could do everything over, like you seem to be doing i would put a firewall in front of all my servers and publish my services to the internal network.