You can deploy Kurento (or Janus itself, for that matter!) inside a subnet of the LAN, to act as a media bridge. Then, if the security group / firewall / whatever is configured so it allows the media bridge public network access, then it could be used to send the data directly to remote peers.
This however would have the bridge in the middle of LAN connections, so it wouldn't be a point-to-point flow, and the server would be able to "see" data passing through it.
There is however some new work on what's called "insertable streams" in Janus, which would allow e2e encryption directly between sender and receiver, thus having the media bridge purely act as a "blind" router, not being able to see the streams passed through it.
Janus has some very recent support for this [0], while this is (for now at least) not standardized and out of scope for Kurento.
[0]: https://www.meetecho.com/blog/janus-e2ee-sframe/