They will work fine behind NAT and the ringing shall stop, that might be the easiest.
If you do not need access for management purposes or have the need to dial the system
ips directly this might be the easiest way.
You can also use a firewall an block first of all sip udp and then possibly
sip-tcp and tls and have that only open from/to the vcs.
The other option could be to disable the sip listening port on the endpoint and use sip outbound.
Not 100% sure if this works fine with a single vcs-e-sp, but I would picture so.
Its more an endpoint thing you are facing rather then something you can fix on the VCS / core.
On the VCS I would check that SIP-UDP is disabled, most scans by today are udp and it might
flood your call logs.
Please remember to rate helpful responses and identify helpful or correct answers.