For anyone else out there that is stumbling on what should be simple (like anyone who firewalls their servers from the rest of their network because they like security), this is how we set it up:
Email (we used EWS) - Incoming: source = AC (Alert Central), Destination = Exchange edge server, service=443
We allow all servers that are between the internal and external firewalls to relay by default, so no rule was needed for outgoing mail.
Solarwinds undates - Source = AC, destinaction = 74.115.12.25, service = 443
Source = AC, destination = 216.205.85.174, service = 443
Orion NPM - Source = AC, destination = NPM server, service = 443
Hopefully we'll get some actual support for this product at some point. This process so far has been very disappointing.