stupid ?!? question : how secure is...

having a router with no services running on it...
using the "standard" masquerading that comes in the debian networking skript 
( the "rusty" three-liner ) and forwarding port 80 to the internal network...

i wonder if i should start dealing with proxies or firewalls ( with ipchains 
policies ) and stuff... is this recommended... and then ( apart from an 
attack from the internal network e.g. a trojan or from misconfiguring apache 
(where port 80 is forwarded to) ) how could anyone gain access to our local 
network ??
i just can't imagine how that could work ??

i would be thankfull for any hints or sources where i can find more info's...

thx peter

