Generally its preffered to put those (untrusted computers in to DMZ), but SME doesn't have built-in DMZ option. Adding extra NIC and modifying firewall rules manualy is task for very advanced Linux admin, not for the average/typical SME user (no offence). Unless you feel up to the task, I would prefer seperate firewall-only appliance for this job. IpCop, monowall, gnatbox lite and many other free small firewalls with very low hardware requirements will work well.