Dear maccamob
Have you downloaded and read the handbook available on e-smith.org, and while you're there you could also read the FAQ, and have a look at the Contributed HPWTO's and RPM's.Your concerns and lots more are already answered.
Re remote VPN via Internet, my understanding is that it is "as if" you were connected locally, so make sure you set up your users access rights correctly and this will stop unauthorised access, and yes sme/e-smith is a firewall. See the White Papers on e-smith .org re security etc.
Regards
Ray Mitchell