To second bday's post-
Our company has been growing by m/a and currently has quite a few machines in non-trusted domains.
We use ISA heavily to support this feature. It's also proven to be a fine and relatively cheap reverse proxy in our mid-size environment (2.5k users). It also works great for proxying Activesync and RPC over HTTPS.
We also use split-horizon DNS and point our internal record to the ISA server. If we need to access OWA using integrated auth (like to embed in a sharepoint webpart) we have a second internal-only record that points directly to OWA.
In a way, our deployment breeds familiarity with the users - they see the same exact OWA logon page regardless of their location.