There is non fro PBX to Trunk.
Maybe you can statically define RTP ports and just allow them?
for me it seems the external one is also only a fixed IP
No, you should show your Screenshots of portforward and outbound
Dont use multiple Interfaces in forwards and dont use source ports