uhm, i wouldnt expose the admin portal on an internal ip to the public unless intentional and yes you can get the ssl host.3cx.tld to function / resolve / use cert as expected via below method on LAN.
Much easier, if you use your pfsense ip as the dhcp dns, is to skip and just do a 'Services / DNS Resolver' and under 'Host Overrides' add your host 'example' then the domain '3cx.tld' with your internal ip. WINRAR! Of course 'example.3cx.tld' is what yours is actually set up as here.
FWIW, i only allow 5060 and 9000:10999 firewall rules and with the source as my sip provider subnet. *simples*
I use AdGuard as my default DHCP DNS, which falls back onto my pfsense DNS, which in turn does the dns overrides check before it hits the cloudflare dns.