It really needs to be segmented in it's own network segment, this is not really an Exchange or server question but a network question. This server needs to be denied access to your internal network on the network layer.
It can be in in the same DMZ and you can create separate rule sets, but than the order of the rules is critical.