berkley,
Are these systems on a vpn, using internal addresses or using public addresses across the Internet? The ports you've opened are primarily for off-site IP phones.
I don't believe we've ever had to open/forward ports unless the customer had completely locked down their VPN. The problem we've usually had, if all ip addressses are correct, is the numbering of the IP Connections. In node 1, we usually number them 6000 (and if there is a PEC, 6010). Then in Node 2 we number them 6001 (6011 for PEC).
Then check your Node Connections in Node Connection Groups that each node is represented by the correct Node Connection Extension.
Hope this helps.