Firewall -> Aliases -> + (add new) -> Type: HostsThen add the external IP addresses that should be allowed and choose a useful name for the alias.Next, edit the firewall rule that allows incoming traffic from WAN to your local PBX. There you select the alias you just created as allowed source.
It looks like you want to use a SIP client behind OPNSense. If so you don't need Portforwarding. Enabling "Static Port" is enough to get proper function of your client.
In Firewall -> NAT -> Outbound, Hybrid outbound NAT rule generation shall be enabled.Then add a rule for Interface WAN, Source address (Fritz Box), Enable Static Port.That's all I needed to make SIP working for inbound calls.