To Zencoder:

I suppose I should have clarified that ports 135-139 should not be wide open to being accessed by the OUTSIDE network. Clearly, in a MS/AD network, those ports are necessary internally.

just this one box on the inside has an external ip for customer connection purposes.
The above quote is from the OP. I still don't understand what "customer connection purposes" means, but several others have already suggested tunneling the traffic, which I would also suggest. If that isn't an option, you could still set up IP ranges that are allowed to connect.



To jbclarkman:

Clearly you are in over your head on this one. Find someone that can help you clean up the mess before it gets any uglier.