If the firewall is behind another router that connects to the web then you need to open a port on the outer router if you use HTTP challenge.
NethSecurity opens port 80 during obtaining LE certs.
DNS challenge is also possible without opening ports.
For more details see Certificates and reverse proxy — NethSecurity documentation