When your central PBX is not on your network, but rather behind a NAT (or on a remote vps), you will definitely (at a minimum) need to open ports for SIP Authentication and for RTP (audio) so that the phones can connect to the PBX.
You are correct. You do not need to do anything to your local...