I have a Watchguard.
I've got UDP 5060, 6000-40000 forwarded.
Like I say, without STUN it works fine and has been fine for weeks. As soon as I put that STUN server in there, incoming calls are only one way. Outgoing it perfectly fine. Take the STUN server out and it's fine again.
The firewall...