Yes, and to add to the OWA question, best practice dictates that you should use SSL connections to OWA, not clear text via port 80, which is the default method. Now, as far as placement of the servers behind the firewall, that's another conversation altogether. :)
