Hey,
ISA ain't bad to be honest.
It's not a hardware firewall but the combination of a reverse proxy makes it nice.
Do your rules allow all traffic from the Internal --> External networks?
ISA ain't bad to be honest.

Do your rules allow all traffic from the Internal --> External networks?