That was it - I'm able to use a local address on either the wireless or lan network for the DMZ host and only my DMZ host is visible to the world. I'll sleep better tonight.

Networking is very painful - this was - what - something like 4 half days of work to figure this out?

Its much slowed down by the fact that everytime you change some address you have to run around and re-init all the devices that used to talk to it - including the device (laptop) you were using to talk to it to change the config.

I expect that by mucking with the port forwarding I can get more machines on the net to do their various jobs.

Thanks again!