Okay.
I see three basic scenarios here - with one constant.
The constant being: I WILL NOT remove my Firewall/Router
I used to think this way myself...You too will come around some day.
A. Put the box in S/G Mode and attempt to negotiate two gateways. (this outta be fun)
You don't need to negotiate 2 gateways. Just don't hook anything to the internal interface. You need the server in S/G mode because it is not safe in S/O mode behind a DMZ. You have to have 2 NICs installed to get the server in S/G mode.
Maybe you don't understand what a DMZ is. It stands for De-Militarized Zone. The DMZ is NOT firewalled and it may allow traffic to the SME box that it can't properly handle if it is in S/O mode. Putting a computer on the DMZ is just like hooking it directly to the internet and we all know how well that works.
B. Periodically reconfigure & jack a workstation (Laptop?) in the DMZ - for the sole purpose of administering the server.
This would be a waste of time. The workstation in the DMZ would become infected within minutes of being hooked up. Again, there is no firewall there.
After you put SME in S/G mode, hook a workstation to the internal interface and administer the server from there. This would protect the workstation.
C. Park the server on the "inside" - - which defeats the purpose of having a DMZ.
Like I said earlier, you will see the benifit of just hooking the server directly to the web. It will replace your router and make life much easier. You don't need the router or the DMZ, SME will do all of it for you.
Whatever you do just remember one thing. SME in S/O mode is not properly protected and needs to be behind a proper firewall. A DMZ is not a proper firewall.