Then look at route-import/export. If BGP and make sure that your subnet mask which you are advertising is matching the configured mask of the networks. If BGP session is up then its routing problem rather than security
If the phones are stuck in upgrade, start with checking the folllowing:
- From the switch, use sh cdp ne det to see if the phone gets and IP address
- Check the connectivity between the phone and tftp server (make sure that all ports are allowed as...