There is a problem with your idea to hack, even thogh he has a "flat" as you put it network, he still has the FIREWALL on the SME server on, and the sme is providing NAT translation, therefore, you cant see past the SME, even if you get past the router.
Plus, with this SME set as a DMZ host on the router, it basicaly puts his SME directly on the web, any firewall on the router, would ether
A: do ABSOLUTLY NOTHING
or
B: get in the way, making it so one one could get to the website/email that he is providing..
Linux firewalls are among the best, so i see no risk with that part of the setup.
However, setting the internal network (green interface, LAN) to a standard class C network type; 192.168.0.n is a good idea, then let the SME server give out the ip addresses to the innermost network.