thanks again everyone.

Why woul ESI not recomend communication over a VPN?

Now a days networks are done via a VPN or Dedicated line. I would not open a port on the firewall for the phones.

Yes, a VPN has overhead, but so does a Cheap firewall that has no CPU power to properly do it's job.
Bandwidth will be determined by the ISP and hardware, If it is bad for a VPN, it would be be for just stright upload for the interent linem and VoIP traffic
(and traffic at the connecting side)

I Thinking about it, if something is set for DoS on the phones, it can not be set right.
a "normal" ping should not cause a DoS alert.