A reverse proxy, such as Forefront TMG or ISA, is recommended to publish the web services on the front end server to the Internet while protecting the server from attack. However, it is possible to use a standard Stateful Firewall and allow the traffic through to the Front End. The configuration is documented in this blog from Ken Lasko.
An alternate solution, again not a supported configuration, is to use IIS ARR to publish the required websites. For a description of the steps involved, see this post at Unify This.