If you press on the "How to resolve?" link, you will get more information on why it is failing. Full cone test, if you check the linked site is Test 2.
When you run the FW Checker, it goes out through the NIC that has a default GW.
What you need to do in your case is create static routes for the SIP and Media IPs of your Provider and force the traffic from 3CX to go out the correct NIC. This should ensure that traffic from 3CX is routed outbound correctly.
Also, in the SIP Trunk settings, in the Options tab, you would need to set the LAN IP of the NIC you have for you Provider in the field "Select which IP to use in 'Contact' (SIP) and 'Connection'(SDP) fields", just select "Use this IP" in the drop-down to enter it.
Last, you must make sure that the NIC you have for your Provider does not have a default GW configured.
As far as I can see, we are set up just like the Asia example in your doc. No DNS servers, no GW and static route in place for the subnet.
The new site is in another county. I am connecting via a softphone on my test PC beside me and connecting via a FQDN:5001 config on the public IP. The phone registers correctly and places calls, but no audio.
Just to rule out the problem being somewhere else:
Do calls between extensions work and have audio?
If you call from your extension to *777 and speak into the mic, do you hear your voice? (this is a echo test number)
In the SIP Trunk settings, do you have "PBX Delivers Audio" checked? (It is also usually best to have "Supports Re-Invite" and "Support Replaces" disabled)
You said you captured traffic in Wireshark. Do you see RTP going from the 3CX server out through the Provider NIC to the Provider GW and vice versa?
Sorry for the delay. Been a really busy time faultfinding this (and a half dozen other things that fell over.)
We've fixed the no audio issue. Was DNS related.