Subject: Looks complete. I would check encrypt on both sides (maybe using a second IP Adress)
And accessing the servers from the web with the notes client might be something to test along the road - it uses port 1352, too. And I would considder some firewall limitations (which IP Adresses may access the port)
I would choose a VPN link between the servers rather than a direct encrypted link.
Secondly I will NAT the public address with the private address of the server(192.X.x.x pointing to Public Ip), by doing so we can regulate the traffic to a greater extent. But in any case Replication over the internet is not good, always good to have a VPN link across the sites and then the normal connection schd’ing.