Looking at the current configuration, the setup looks okay to me. It is organisational requirement and invidual preference which may utimately decide what king of network network you'd like to setup. Some people place their web-servers/SPS servers in DMZ network while some would go with the network design you have.
You can definitely go ahead with this network design. Make sure that you run ISA in firewall mode to take it's full advantage. You can run ISA as a edge firewall facing the internet with an Static public ipaddress on the external NIC. regarding your reverse proxy/publishing requirement of website, you can surely host it on your internal SPS server and make that available to the external world.
You can make use of SSL using certificates to make your website secure. As a reference, you can use the folowing article to publish website. This article talks about publishing OWA website using SSL. in similar fashion, you can publish any website on IAS to be available for external users.
Using the 2006 ISA Firewall (RC) to Publish OWA Sites
http://www.isaserver.





by: QuoriPosted on 2008-08-19 at 17:45:10ID: 22265239
You could setup the ISA box in 3-leg perimeter mode and have one of the legs be a DMZ for published servers.