said by bclbob:x51: I think what you need to do is get 2 NICs for the webservers, one side plugged into the U-Verse gateway for the public IP and the other set to your internal network.
Obviously you're going to need to have firewalls on each of the machines, since the idea is you're going to do the DHCP dance to get those machines external IPs.
Well with the publics on the machines, I can still use the RG as a firewall... but it all seems to come back to 2 NICs. The one solution from djrobx with the VM linux firewall is the only way I know to avoid it.