1) sudo NOPASSWD is the moral equivalent of making that user root. I don't care for it. My preference would be to configure sshd_config with "PasswordAuthentication no" and continue to use passwords in the regular way, with password complexity enforcement if your distribution supports it. I'm not going to blanket condemn ssh public key auth, since it's generally smart. However, you can not enforce a requirement that the public key be encrypted on the remote host. If someone is undisciplined with the distribution of their public keys they can end up turning a single box exploit into free reign of the network, particularly if NOPASSWD is enabled.
2) I prefer manually editing iptables rules myself, using -I and -D. It's certainly not intuitive at first blush, more like using "ed" than "vi". I've gained an appreciation for using the "-m comment -comment 'this rule does blah'" construct. The benefit of this model is that an unfamiliar sysadmin won't immediately know that a host has another FW package installed, but if a change is needed everything is documented and commented in an "iptables -L" -- a standard diagnostic command. Furthermore, firewall rule generators often create unreadable rulesets, making diagnosing specific problems tough.
A specific nit I have against Shorewall is that it requires (last time I checked) you to edit a bunch of different files, using boilerplate recipes that aren't really much simpler than just writing the rules yourself. It could be a big win if you had multiple platforms to support, I suppose.