The unsafe ports should be inaccessible on the LAN as well, according to project manager.
But I suppose since it's just a redirect, I can inform them that it doesn't really present a security breach, since they've approved the use of https anyhow.
Thanks!