If port 25 is stealth from the internet, you cannot receive mail from internet hosts. You do want to configure your system such that it does not relay blindly, which as I recall is somewhat difficult with Exchange. I found a registry hack for limiting relaying, but can't recall where it is. I hope that Microsoft has learned from their mistake and made relaying rules a menu driven or INI file configuration in Exchange 5, but I wouldn't bet on it.
Another option, although a poor one in my opinion, that I have seen others use is to let your ISP be your internet mail server, and configure exchange to poll the mail on a routine basis. I believe that the minimum configurable value for Exchange was 15 minutes the last time that I checked. That is intolerably slow for people who are used to the instant gratification that is available by making your mailserver internet accessible. I've had to "fix" a couple of these setups.
Personally, I prefer sendmail and Postfix. It is simple to configure them to be internet safe (blocking blind relay).
pansophic