nerdexam
Microsoft

MS-720 · Question #145

You have a Microsoft Teams Phone deployment. You are deploying Direct Routing. All users have a SIP URI in the format of [email protected]. The Session Border Controller (SBC) is named…

The correct answer is D. The firewall blocks traffic to the signaling port on the SBC. Option D is correct because Direct Routing relies on SIP TLS signaling (typically port 5061) between Microsoft's infrastructure and the SBC - if the firewall blocks inbound or outbound traffic on that signaling port, the SBC cannot complete call setup and will generate…

Monitor and troubleshoot Microsoft Teams Phone

Question

You have a Microsoft Teams Phone deployment. You are deploying Direct Routing. All users have a SIP URI in the format of [email protected]. The Session Border Controller (SBC) is named sbc.voice.contoso.com. When troubleshooting errors on the SBC, you receive the warning shown in the following exhibit. What is a possible cause of the issue?

Options

  • AThe tenant is missing a vanity domain of voice.contoso.com.
  • BThe firewall blocks outbound traffic on port 443 to Microsoft Teams.
  • CThe firewall blocks inbound traffic on port 443 to the SBC.
  • DThe firewall blocks traffic to the signaling port on the SBC.

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    17% (6)
  • D
    74% (26)

Explanation

Option D is correct because Direct Routing relies on SIP TLS signaling (typically port 5061) between Microsoft's infrastructure and the SBC - if the firewall blocks inbound or outbound traffic on that signaling port, the SBC cannot complete call setup and will generate connectivity warnings. Option A is a plausible distractor, but a missing vanity domain (voice.contoso.com) would prevent the SBC from being paired in the Teams admin center entirely, not produce a runtime SBC-side warning during active troubleshooting. Options B and C both reference port 443, which is used for HTTPS/management traffic, not SIP signaling - Direct Routing does not use port 443 for call control between the SBC and Microsoft. Even if port 443 were blocked inbound or outbound, SIP sessions operate independently on their own port, so those choices describe the wrong protocol layer.

Memory tip: Think "D for Direct Routing's signaling Door" - the SIP TLS port (5061) is the door calls walk through, and blocking it at the firewall is the most common runtime failure. Port 443 belongs to the web/management layer, not the call signaling layer.

Topics

#Direct Routing#SBC#Firewall#Network Ports

Community Discussion

No community discussion yet for this question.

Full MS-720 Practice