For applications that are protected by a firewall and depending on your organization's security needs, two options exist:
Allow inbound access from Jamf Connect's Zero Trust Network Access via reverse proxy or a firewall exception.
Establish a secure connection between Jamf and your organization's infrastructure. This is typically involves an IPSec connection between existing network equipment or a Jamf-provided Linux VM image.