is there any packet inspection, SPI, going on? You need to remove RTP from these zones if configured. Other than that, it all points to the firewall in my opinion. What ports are open and are they open for both source and destination? You would expect with a vpn that all traffic was allowed...