I have spoken to the guys would really have development this and they are the guys from Linksys. the is before cisco and linksys became one. There advise was alway leave the firewall as is, and just use the forwards as to not unintentially allow unwanted traffic to flow in. This is why there VPN client doesn't need any extra port open to work.