Forwarding all ports would make it exactly the same as connecting the SME directly, without the other device. I don't know of any examples, but this would help if there were some sort of bug affecting SME, that your other device didn't pass on (i.e. the NAT conversion filtered out the bad data before it got to the SME). As the manual states, SME doesn't accept incoming connections except on the public services (web, mail, etc.), so even without your other device you're quite secure.