I am trying to make them as secure as possible. I agree that they could easily be kept "inside" the network but a management goal is to remove all devices that Cisco stops providing software updates for. I am hoping that removing all functionality other than voice requirements and putting them on the other side of a firewall will to convince management they are "safe" for a few more years - at least until we move to SIP or replace with much less expensive routers. I don't think many people are trying to hack in through B1 lines anymore and we need them for 911.
I would like to hear from others that are keeping 2900 routers to help build my case so I can move to Meraki sooner.
Thanks for the response.