Thanks for the fast reply!
We don't employ a site to site VPN, so this would just be client devices having the ability to reach the internal IP for any new RADIUS server we set up for internal authentication purposes.
I suppose I could setup a test SSID and set the RADIUS server IP to a different IP than our production server and see if the firewall rule updates after I apply changes.
I'm just not sure if the server IP would then be removed from the Inbound firewall rule once I remove the test IP for RADIUS from the test SSID.