This can be tricky as if you are using the 3CX phone provisioning templates to setup the remote phones the templates by default need to be modified to use the correct IP address in the phone template.
Also, you would need to port forward the correct ranges of udp / tcp ports for each extension.
The "supported" 3CX method is to use the 3CX tunnel app or VPN.
You could bypass a lot of this headache by using a Session Border Controller.
We offer a hosted SBC that re-writes the packet headers of the remote phone traffic so that you wont need to use VPN / Tunnel and do not have to jump through hoops to do all this routing through many port forwards and firewall changes.
Let me know if you want to test it out and we can set you up for a trial.