It is "port forwards" in the interface to create DNAT and redirect rules.
alg (aka nat helper) assignment is reachable via firewalls 1st page -> edit each zone -> conntrack -> disable helper auto-assignment (unless you installed nat helper kmod list will be empty)
By default no helpers are installed, so settings do nothing. No helpers are normally needed at all, disabling auto-assignment just prevents them all from acvidentally ctivating.
you might need one for (windows) ftp, or one for (windows) pptp, but normally none
Neither setting looks correct at all. Change minimal amount of settings as specified - port and protovol(s) and internal IP in first tab and sourcr addresses in second.
My reading of the doc... (254.50 is the supposed voip gateway)
Edit that in a text editor 4x
Append resulting file to /etc/config/firewall
Then find back and enable 4 rules
(a bit of discomfort to have MxN rules but will work)
That looks better... You can just add my 4 rules and enable them.....
You can cut half millisecond on redirected connection establishment by testing this PR https://github.com/openwrt/firewall4/pull/77
Edited the example 4 rules with your PBX "collector" IP
Why I doubted TCP+UDP - voip phones I ever saw used only UDP for (s)RTP, just checked that wikipedia disagrees