WHat needs to be done to get this to work ebhind firewall?

I am being told that I need to forward to 1 public addy for signaling (and enter that into phone for CA)- port 2427

THEN, forward another public IP to the internal ip for media with ports 16400-16499 and then it should work.

I even went so far as creating 1-1 NAT with each Ip going to it's corrwsponding internal IP and allowed ALL ports.

I have the Public IP for signaling in CA1.

I have been able to get the sginaling, but no voice over the phone.

Anyone make this work successufly with a REAL internal Firewall on the office side (not a little Linksys NAT box)?