Hello,
Firstly I'd get gamma to relax that firewall and give you a routed IP then get a Draytek 2862 and use that as your router into the cisco.
Every single time gamma have configured a cisco for me it's never been correct first or second time, additional to this I have had them randomly remove port forwards causing my customer to go down,
A DSP-S would sit well for your size.
In terms of your VLAN's, I mean it's up to you, I have lots of small customers with VPN's which pass voice with no VLANS.
Haven't used the IOS softphone unfortunately however if it's anything like other manufactures it will be a username and password with the public IP of the site unless you have a FQDN (unsure if it even supports that)
Calum M
ACSS