There are multiple approaches to solve this depending on your situation. You could just open a port in pfsense and redirect port 8883 to UMH.
Other option would be to setup a second broker in the cloud and bridge the data to it. Like a DMZ. With this, there would be no need to open any ports
Then create your PKI infrastructure (I could help you with that) and add the certificates there.