As the Data Collector ultimately needs to talk to the end devices directly, you have one of two options.
1. Allow the current Data Collector(s) to communicate through the DMZ to the end devices
2. Install a new Data Collector within the DMZ and allow communication between the Data Aggregator and the new Data Collector
As for what lines of communication you need to keep open, please refer to the Performance Management documentation link below: