Both solutions will work as I am sure you are aware, but in light of the fact that you do want to control certain types of traffic based on subnet addresses then the router solution would seem to be the sensible approach, particularly as you will want to implement QoS certainly once you start to int...
Can you give more inforation on this? Are you saying nobody can currently connect to the server unless they first access the Broadband, or you want clients to connect to Broadband before the server????
Feklar is right, if you mess up by having your general firewall rule set up, you could rule out the use of more specific rules. One general rules of Firewalls is to have more specific rules near the top and catch all rules nearer the bottom.