Re: Firewall scenarios
The email / web server could be behind the firewall, however you would need to port forward the correct ports. You'd find this kinda setup in very small businesses and home networks.
A more common setup would be the use of a DMZ which is basically a separate network for devices that need to be visible over the internet. You'd have a router with 3 network interfaces, your standard LAN which would have no ports / services visible over the internet, and your DMZ which would have ports open to the internet, and on some routers this interface could have many IP addresses for each server.
Than sometimes you do have servers directly connected to the internet, or behind transparent firewalls.