Best way to pass-thru Public IP with PfSense

I have (5) five Public IPs that I pay for each month. I use the first one for everything but VOIP. I use the 2nd IP directly on my VOIP-PBX so I don’t have to NAT. I would like to run the 2nd IP thru a firewall such as PfSense for my firewall. What is the best way to protect my VOIP PBX, can I use PfSense with VOIP to avoid using NAT and what is the best way of doing this. TIA

I never set it up that way, but they have it documented here

Thanks for your response. How would you do it?

We assign all the IP’s to our WAN and have pfsense and use NAT.

