IMO the SME works best in server/gateway mode without a router. You'll only complicate things with a router, especially on a home network. Do you have any specific reasons that you can't set this up server/gateway? (for example, i have 30 locations that i can't get the sme to vpn simultaneously to all, so putting out-of-the-box vpn routers makes everything nice and easy).
if you're intent on sticking with the router, on the router forward the port to the SME. then from the SME forward the port to the workstation (static hopefully).
BTW, I must have played that game for 4 days straight, morning -noon -night. no lie.