Here's a good write up on how to configure Solaris 10 to use NAT (with ipfilter) in the global zone to filter traffic to the private interfaces in the non-global zones.