Ask which service needs to be reachable
A carrier may need to send signaling and media to your PBX. Remote phones need an approved connection path. Neither requirement automatically means the management interface or every listener should be publicly reachable.
Example defensive architecture. Source restrictions, authentication, update policy and call permissions work together.
Build an access matrix
For each service, identify permitted source, destination, protocol and purpose. Use provider-documented networks where applicable and a controlled remote-access architecture for administrators. Confirm the policy for both IPv4 and IPv6.
Do not confuse obscurity with control
Changing a default port can reduce some noise but is not an authorization boundary. Authentication, software maintenance, rate controls and restricted dialing remain necessary. Encryption protects configured traffic paths but does not prevent an authenticated account from abusing granted permissions.
Verify the actual deployment
Inventory listening services and compare the firewall to the intended matrix. Remove unused exposure through a planned change with a recovery path. Test legitimate incoming, outgoing and remote calls after hardening. Keep emergency and continuity arrangements documented separately with the carrier.
Sources & applicability
Primary references for the technical details above. Operational examples and planning checklists are VoIP.info editorial guidance.