Need a sbc. Even if you port forward the public IP to SM, the media IPs in the SDP of the sip messages will be coming from CM and point to the internal IP of a gateway. You need a sip-aware box on the Internet facing edge to rewrite those IPs in the SIP messages to the public IP you'll be using.
Avaya SBC documentation or white papers for remote worker spell it out. I'm sure if you put a little elbow grease in that you can make it work with the sip stack in most commercial firewalls if you don't want to go down the path of an Avaya SBC.
Depending on when you bought and the licensing you have, you might be entitled to run an Avaya SBC with minimal licensing additions. Though, at 6.3, that's probably not happening until you upgrade.