...
Your devices need to be able to communicate directly with each other. ZeroTier users UDP hole punching to do this. It’s a similar process to VoIP STUN/TURN.
The difficulty for strict firewall configurations is: the my.zerotier.com controllers and your devices are on dynamic IP addresses and are listening on random UDP ports.
...
9993
Secondary Port, randomized each start up and after being “offline” for too long.
Random Port for UPnP (UPnP is not required for ZeroTier hole punching to work)
If you allow outgoing 9993 and incoming return traffic, you may have some luck.
...