Accessing machines behind a firewall

I am helping out a local ISP who has a few NT boxes live on the internet
serving up web pages.  We realize how insecure this is and would like to
firewall them, allowing only web and/or ftp traffic.  Is this possible/
desireable or does it just defeat the purpose of the firewall?

