A 3CX SBC is not just a gateway... it's a multi-service device; it handles NAT traversal on its own via an encrypted tunnel. It also acts as a PnP relay. So, it's nothing like what an FXS or a phone (without router functionality) could manage.
I'm not sure you fully understand the complexity of managing NAT.

Your device (FXS) needs to identify its public IP and the port it's using before sending SIP packets.
The goal is to specify the correct source IP address and port in the SIP packets so the server replies to the right source.
You mentioned that your device manages NAT – great, but how exactly? RPORT? STUN? TURN? ICE? SIP ALG (router) ?
Have you confirmed that it's working correctly?
Even if you manage to register, it doesn't guarantee that calls will work, and if calls do work, it doesn't guarantee that the audio will function properly. And even if the audio works, it doesn't mean your device will remain stable and operational.
There are many factors to consider.
3CX provides the solution: install an SBC. You can even install it on a Windows computer, as long as it stays on and is always connected to the internet.
If you're unable or unwilling to install a 3CX SBC and rely on the FXS device to manage NAT traversal on its own, you should contact the FXS manufacturer for assistance with its NAT traversal features.
@JohnS_3CX shared an analogy that I love
here :
So, when you say that NAT traversal works in some cases and not in others, it's like asking me why rolling the dice sometimes gives you a six and other times a one.
( John didn’t explicitly grant me reproduction rights, but I imagine he won’t mind, lol.

)