You can just put the IP address of your virtual machine as a DMZ zone in your router. That'll forward EVERYTHING to your virtual machinet. For better or for worse, you may discover that many of the really troublesome ports are also blocked by your ISP, so you may not get hit by the more common attacks.
Be sure you have a firewall running on your host machine, and any other boxes on the same subnet as your NT virtual machine. And be sure all the "real" computers are fully patched, both the OS and any running applications, and have active and updated AV software.