What kinds of third party SIP are you all having so much issue with? I manage a lot of accounts using the big, hosted providers and plenty of the endpoints sit behind Xfinity/Comcast boxes without issue.
The dropping registrations just sound like timer and firewall configurations. By rule, I try to always go bridged mode with Comcast provided boxes, but even when not I can't recall having an issue like this except via the normal things like ALG being enabled or some type of security inspections causing trouble. And TLS is the way 100%