Note that the SME /etc/rc.d/init.d/masq script that sets up the ipchains firewalling also turns on the kernel rp_filter source address mechanism so there is not much chance that anyone on the outside can get packets through with an inside source address, no matter how much they know about them.