Hello Ben,
As you indicated RTP and RTCP are not listed on the match protocol ports of ZBFW. You need to use access list instead of match protocol and allow the traffic based on ACL's.
To be honest with you I am not sure if with "inspect" action its going to work for you, you can try it but if the issue persist you may want to use "pass" and allow the packet both directions (in-out and out-in).
Regards,
Juan Lombana
Please rate helpful posts.