Reachability changes
A VPN can provide a controlled private path to the PBX. It does not automatically configure the phone or guarantee low delay. Signaling, provisioning and media may use different destinations, so verify the route for each.
10.0.0.10 is an illustrative private address. Both directions traverse the NAT/firewall; signaling success does not validate SDP media reachability.
Check overlapping networks
A home subnet can overlap the office voice subnet. Split routing can send some traffic outside the tunnel. Inspect the actual destination path instead of relying on the VPN connection icon.
Revisit NAT assumptions
A phone previously using the public internet may no longer need the same advertised-address workarounds. Compare the negotiated media addresses with the new topology. Account for encapsulation overhead and available throughput.
Exercise recovery
Test registration, incoming calls, sound, hold and transfer, then repeat after a controlled tunnel reconnect. Record whether the phone recovers automatically and how long it takes. Keep management permissions restricted inside the VPN; network access should not grant unnecessary administrative authority.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.