PS, Pardon me if you know all of this already...
I would agree with acewarlock. LD 15 CDB OPT CFF will permit phones to forward offnet if the phone can call the number directly. CFF stands for "Call Forward, Forwarder" which means that the FRL associated with the outbound call is taken from the forwarding TN (the TN where you program the FDN) instead of from the originating TN (which would be the trunk the call came in on.)
Using LD 23 ACD-DNs with NCFW (small typo on acewarlock's part but still essentially accurate) would bypass FRL restrictions in your ESN (electronic switched networking) datablock by using the ACOD on the out-bound route.
And, yes, changing Customer Data Block (CDB) Options (OPT) from CFO (Call Forward, Originator) to CFF does open your PBX to toll fraud if any sets in your building are configured with CFXA, CFW keys and an NCOS sufficient to reach off site (or the ability to dial the ACOD directly).
You can find all sets with CFXA using the LD 81 LST FEAT CFXA routine.
Code:
OVL000
> LD 81
REQ: LST
.
.
.
FEAT CFXA
FEAT
.
.
. output
Good news for us today, the customer was made to realize that the toll fraud issue preceded the replacement of the voicemail system which died in the beginning of December 2007. We're no longer on the hook for the system being changed during the rebuild work, the issue precedes our company's involvement with the customer.
Bad news for them, their national long distance provider is trying to hit them for the full cost of every fraudulent call. Semi-hopeful news for them, we also happen to be an agent for that long distance provider so we're going to see if we can help get a waiver on some or all of the fraud. (Some of it is so very clearly fraud...)
Specifically the problem with this site was the voicemail ports were configured with NCOS 5 (FRL 5) and the ESN (specifically SPN 011) was configured with an RLI that had an FRL of 0... which meant that any phone was permitted to dial internationally. Since the issue arose, the customer has agreed that there is no need for voicemail to call off site for any reason.
(The DATE output on when the TN was last changed is invaluable in showing when the data was last changed. Looks like someone many years ago left the back door open and the problem only recently started, or perhaps only recently became excessive.)