This is short and sweet.  If you want to get Verizon Wi-Fi calling enabled on a restrictive network here is what you need.

UDP ports 500 & 4500 open to sg.vzwfemto.com. That FQDN comes from https://www.verizonwireless.com/support/knowledge-base-25525/.

There are lots of posts online with specific IPs but I set it with that hostname and everything seems to be working.

As for my specific set up in pfSense I have our phones set up with static IPs and then created an alias for them. I then created an alias for the FQDN above. Finally, one firewall rule each for the two ports.