Hi Arch,
1) 443 (SSL) from Endian to Exchange only
2) Created a self signed certificate using Active Directory, all members of the domain trust it by default
3) Yes, and working well on Outlook, Nokias Exchange Client and iPhones
4) Yes, but taking into account 2, only those on laptops that have joined the domain can do so without too much fuss
5i) We created a rule that only allows access to Exchange from predefined IP addresses, yes it can be a pain to administer, but it takes seconds to set up a new IP address and keeps our Exchange box that little bit safer
5ii) We ended up creating another Exchange server and making it a front end one, seems to solve loads of funny problems with exchange stores etc
Have fun, but it makes life so much easier in the long run!
Gyp