On the firewall I would set up NAT and block all unnecessary traffic until the layer 7 (have a proxy function). If you configure it like this, it will be easier to put an IDS between the router and firewall and the traffic analysis will be easier. This also allows you to put a host "on the Internet" behind the router, but in front of the firewall.

