MS-720 · Question #63
You have a Microsoft Teams Phone deployment. You are deploying Direct Routing by using a certified Session Border ControNer CSBC). The FQDN of the SBC is sbc1.contoso.com. You use signaling port…
The correct answer is A. The firewall blocks traffic on port 5067. Option A is correct because Direct Routing requires the SBC to communicate with Microsoft's SIP proxy over the configured signaling port - in this case, port 5067. If the firewall blocks that port in either direction, the SBC cannot establish a SIP trunk to Microsoft 365, which…
Question
Exhibit
Options
- AThe firewall blocks traffic on port 5067
- BLocation-Based Routing is enabled for the SBC.
- CCalling plan licenses are not assigned to users.
- DThe SIP options are disabled.
How the community answered
(45 responses)- A73% (33)
- B9% (4)
- C13% (6)
- D4% (2)
Explanation
Option A is correct because Direct Routing requires the SBC to communicate with Microsoft's SIP proxy over the configured signaling port - in this case, port 5067. If the firewall blocks that port in either direction, the SBC cannot establish a SIP trunk to Microsoft 365, which is exactly what the Teams admin center error reflects (typically a "TLS connectivity" or "SIP options not received" failure).
Why the distractors are wrong:
- B (Location-Based Routing): LBR restricts call routing based on network location but doesn't prevent calls outright or cause SBC connectivity errors in the admin center.
- C (Calling plan licenses): Direct Routing is specifically used instead of Microsoft Calling Plans, so Calling Plan licenses are irrelevant - users need Phone System licenses, not Calling Plan licenses.
- D (SIP options disabled): SIP OPTIONS is a heartbeat mechanism; disabling it may affect health monitoring but is not itself a cause of the firewall blocking traffic. The symptom described (error in admin center, no calls) points to a connectivity/transport-layer issue, not a SIP OPTIONS configuration setting.
Memory tip: Think "port = door." If the signaling port (5067 here, 5061 for default TLS) is blocked by a firewall, no SIP traffic can flow - it's like locking the front door of the SBC. Always verify firewall rules allow both inbound and outbound traffic on the configured signaling port between the SBC and Microsoft's IP ranges.
Topics
Community Discussion
No community discussion yet for this question.
