For hybrid you need port 25 to the Exchange Server directly or the Exchange Edge Role from Exchange Online
https://learn.microsoft.com/en-us/exchange/hybrid-deployment-prerequisites#hybrid-deployment-protocols-ports-and-endpoints
https://learn.microsoft.com/en-us/exchange/transport-routing