There is no need to open any special ports between the HQ and any Branches when using QCS.
This tool will collect the data and will send it per e-mail to the partner, so as long as e-mail (SMTP) communication is working the tool will work. Of course the tool itself will need access to the AD (DC) and to Exchange (server), but inside a company such things are usually not firewalled.
For more information please see QCS documentation, for example "How it works".
Below is an excerpt from the document:
Secure Solution
Collaboration Services is a secure directory, calendar, and free/busy data synchronization solution. It has the following benefits compared to other directory synchronization solutions:
Between the HQ and Branches
• No trusts, VPN tunnels, or supplementary accounts between forests are required.
• You do not have to open directory access port (LDAP port) for outbound access to let other
forests’ accounts query your directory and Exchange data.
• No forest uses any account from any other forest.
• Full administrative autonomy is preserved: the administrator of each forest chooses which
objects and data from that forest will be available in other forests, and which objects and data
from other forests will be applied and available in his or her own forest.
• All Collaboration Services communications between forests are encrypted and signed.
• No security-related user data, such as security IDs (SIDs) or passwords, is ever transmitted or
stored anywhere.
Between the QCS Server and your AD \ Exchange environment:
The way native Microsoft tools (i.e. Active Directory Users and Computers, Exchange Management Console, etc.) would traverse Firewalls to communicate would be similar to how QCS would communicate within your environment.
The following ports need to be opened to allow for dynamic RPC communication:
RPC Endpoint Mapper TCP/UDP 135
Windows 2003 Ephemal Ports - TCP/UDP Ports 1024-5000
Windows 2008 Ephemal Ports - TCP/UPD Ports 49152 - 65535
Further Communication from QCS to retrieve Active Directory Information, and for name resolution the following ports will need to be open to the appropriate Servers:
LDAP - AD Lookups: TCP/389
Kerberos: TCP/UDP 88
LDAP Global Catalog: TCP/3268
DNS: TCP/UDP 53
WINS: TCP/UDP 137
Also confirm that the Firewall is allowing multiple ports to be open at a given time. Sometimes there are limits on firewalls to only allow a couple ports to be open at one time.