Start with traffic roles
The administration interface is not the SIP listener, and the SIP listener is not the RTP media range. Build an inventory of each required service, its source, destination, protocol and purpose. A generic instruction to open VoIP ports is too imprecise for a secure deployment.
Example defensive architecture. Source restrictions, authentication, update policy and call permissions work together.
Use the actual configuration
Read the PBX's configured listeners and media range and the carrier's documented signaling and media networks. Defaults in another tutorial may not match your installation. Remote phones can have a different access design from a fixed-address carrier.
Diagnose with observations
Review relevant allow/deny counters and a bounded packet trace around one failed call. Confirm whether traffic reaches the boundary and whether the return path is valid. A lack of replies can also involve routing, DNS or a service that is not listening.
Keep management restricted
Do not expose administrative services just because phones need to register. Apply the smallest justified change and test the intended call flow. Remove temporary diagnostic rules afterward and retain the reason for each permanent rule in the operating record.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.