[fw-wiz] Communication Device Protocols from External router direct through Firewall

I am trying to determine the risks of allowing the following protocols
from my external routers directly through to my internal LAN versus
setting up a DMZ proxy:

SNMP (polling / traps) Syslog, SSH, Tacacs, and Netflow

I know that SNMP and Netflow might provide infrastructure information, but
I fail to see how a DMZ proxy makes this activity more secure given that
information from the DMZ to the firewall would not be encrypted.

Furthermore, SSH and Tacacs are already fully encrypted.

Any advice would be appreciated.


