The capture was not useful. It only showed INVITEs coming from 3CX to two different locations. The capture lacked any RTP details so it is unknown as to which call had an issue as well as which site. The capture did not show the call origination, that being what caused the INVITES to be sent. I assume this is due to the nature of the hosting and that the provider calls are being handled by a different interface than those being sent to the remote locations.
It helps to know more about the situation. So, here are some pointers:
1. Do not post captures that show the public/accessible FQDNs/IPs of the sites. Others may be able to view and use the info to target your system for attacks. Edit the post such that these are identifiable as being internal or external, but without blacking the info out completely so it can no longer be discerned by those that are trying to read them.
2. The good site info is informative as it does imply that the traffic coming in and out of 3CX for the good site is OK, so 3CX is OK. The VPN has no bearing as no VoIP related traffic is seen across the path.
3.
he bandwidth and speeds necessary for VOIP
is a statement that lacks detail to support the claim. a) we do not know if the call issue was heard in both directions and if only one direction, which way? b) we do not know the data needs of the site that is having the issue, which traffic direction may have more utilization and if any QoS is employed. Fiber/Cable or ? Asymmetric or Symmetric speeds? Granted, the voice needs are likely under 500Kbs in either direction, but if someone in the organization does something that involves traffic going up or down, how is the voice traffic protected such that the data traffic doesn't impinge on it by taking all available bandwidth? You have ruled out bandwidth as an issue, but could it be?
4. Are all calls to the problem site affected or is it random calls?
5. What codecs are in use?
6. If a cable modem is in use by your ISP, have you tried to reboot same along with the router?
Cable modems use a mechanism my which they communicate to the CMTS system so they can adjust the RF transmit levels to be optimized for a given site as all may be somewhat different. Similarly, the modem will also adjust the attenuation on the receive side for the same reason. A reboot will cause the training to occur.
7. There are various web sites that offer some form of VoIP suitability testing. Some are free and some paid, but it may pay you to do a search and find one that will simulate the needed number of call that you envision and that will test for some amount of time. Look for latency, jitter and packet loss as testing criteria. This may tell you if the ISP has an issue as these will not get to the LAN side.