VOIP HOTSPOT BYPASS

Hello Guys,
I have Cisco sip soft phones deployed in my firm. The Cisco router is directly connected to the internet while the two mikrotic routers are connected between the cisco router and the lan network.
The mikrotic routers provide authentication for users while cisco router routes the authenticated users to the internet. This is the challenge that i am facing

  1. when a user call another user after hotspot authentication,the audio and video work very well
  2. I dont want the users to be authenticated through the hotspot before they can make local calls.However when a user tries to access,the internet,the hotspot should provide authentication.
    I have bypassed the ip address of the call manager server using the ward garden IP list and IP binding .Now,the users can sign in and call but the audio and video are disabled.
    I searched through google that Cisco jabber (the soft phone) users the following port nos 33434-33598 for video stream. I have added these ports in the ward garden IP list but to no avail
    can someone assist me? Thanks in anticipation

how can I prevent ghost calls from microtic routers. On some phones this problem can be solved with “sip trust only: enable” option. How do we solve this problem in microstructure?

Example problem description link:
https://wiki.voip.ms/article/Sip_Scanner_Ghost_Calls
https://www.linkedin.com/pulse/how-block-ghost-calls-coming-from-100100010000-your-yealink-nadeau/

http://prntscr.com/heltjv

Hello,
Still waiting for responses am am stuck

To all those that might have this challenge,just bypass the port nos in the ward garden ip list.do not specify the ip address but the ports nos for the video signals