Just to avoid any confusion, let's please take this from the top.
Check the steps below,
confirm every step and let us know at which step you get stuck and why:
1. Since you are using a site-to-site VPN and local routing exists between the IP Phones and the 3CX PBX, completely remove the 3CX SBC.
2. Make sure that the devices are running the
3CX Supported firmware version and that they have been factory reset. Confirm that you are now running firmware version 6.3.0.14929.
3. Access the Management Console, go to Extensions, Edit an Extension and go to Phone Provisioning. Add the Polycom device from the list along with its MAC address(just the 12 characters) and then make sure that the Local Lan provisioning method is selected. Click OK on the top.
4. Go back and copy the Provisioning link from the Phone Provisioning tab of the extension and then access the Device's Web UI using it's local IP in a Web Browser. (Make sure that the provisioning link you copied contains 3CXs local ip address and not the FQDN)
5. Navigate to Settings >> Provisioning Server, select HTTP where it says "Server Type" and then paste the provisioning link you copied in the "Server Address" field. Clear the "Server User" and "Server Password" fields and save.
6. The IP Phone should now reprovision, if it does not after a while(2-3 minutes) reboot it and check again.