This is short and sweet. If you want to get Verizon Wi-Fi calling enabled on a restrictive network here is what you need.
UDP ports 500 & 4500 open to
sg.vzwfemto.com. That FQDN comes from https://www.verizonwireless.com/support/knowledge-base-25525/.
There are lots of posts online with specific IPs but I set it with that hostname and everything seems to be working.
As for my specific set up in pfSense I have our phones set up with static IPs and then created an alias for them. I then created an alias for the FQDN above. Finally, one firewall rule each for the two ports.