That's true.
Our hospital uses an external firewall cluster for all services.
E.g. Citrix Netscalers for remote access are placed behind that
In our case the MBG's ar not behind it, because, I think, it's not needed because our telco uses a direct IP link for vice only.
We do have a MBG for micollab facing the internet.
That box is placed in our DMZ.
I'm a customer, let me explain my thoughts.
I understand the discussion!
But... why do you care?
If you manage and install the phone systems and the customer trust you and Mitels technology and does not need an extra firewall: great.
If they are questioning the technique, it may be (corporste)company policy or whatever reason:
It's probably more work for you, I know setting up voice in a firewall costs the customer -and you!- probably more time. One-way audio is one of the commonly known issues.
Troubleshooting afterwards also costs more work.
But: that's up to the customer.
Explain the options, share the docs -as you did-, and let the customer decide.
But it's fair to be clear: they'll have to be ready for extra work themselves and pay for your extra work now and probably troubleshooting hours in the near future.
Don't argue, that's not professional, and as a (technical skilled) customer: I like to have options, and will probably choose the best for our hospital, also with the company-security-policy in my mind.
But in a commercial business, the manager maybe like to choose the cheapest option.
You never know. And if you don't argue: it doesn't matter and you get paid eather way and are respected for your work