It can have a private IP there is no reason to have a DC publicly accessible. if you need to authenticate to it externally you should set up vpn tunneling.