There is no additional authentication except for the "PHP suEXEC Daemon mode" as the PHP main process running as root user.
This mode cannot be used for remote PHP server due to that the master secret keeps changing after each server restart.
Yes, firewall will be the only way to protect the remote PHP server port, and it should be protected against accessing from public network.