nerdexam
Microsoft

MS-720 · Question #99

You have a Microsoft Teams Phone deployment. You are deploying Direct Routing. All users have a SIP URI in the format of [email protected]. The Session Border Controller (SBC) is named…

The correct answer is B. The firewall blocks traffic to the signaling port on the SBC. Option B is correct because in a Direct Routing deployment, Microsoft Teams must be able to send SIP signaling traffic inbound to the SBC on its configured signaling port (typically TCP/UDP 5067 or 5068 for SIP over TLS). If the firewall blocks this inbound path, the SBC cannot…

Monitor and troubleshoot Microsoft Teams Phone

Question

You have a Microsoft Teams Phone deployment. You are deploying Direct Routing. All users have a SIP URI in the format of [email protected]. The Session Border Controller (SBC) is named sbc.voice.contoso.com. When troubleshooting errors on the SBC, you receive the warning shown in the following exhibit. What is a possible cause of the issue?

Options

  • AThe firewall blocks outbound traffic on port 443 to Microsoft Teams.
  • BThe firewall blocks traffic to the signaling port on the SBC.
  • CTLS 1.2 is enabled on the SBC.
  • DMicrosoft 365 Phone System licenses are not assigned to the users.

How the community answered

(45 responses)
  • A
    11% (5)
  • B
    78% (35)
  • C
    4% (2)
  • D
    7% (3)

Explanation

Option B is correct because in a Direct Routing deployment, Microsoft Teams must be able to send SIP signaling traffic inbound to the SBC on its configured signaling port (typically TCP/UDP 5067 or 5068 for SIP over TLS). If the firewall blocks this inbound path, the SBC cannot receive call setup messages from Teams, which manifests as SBC-side warnings about failed or dropped connections.

Why the distractors are wrong:

  • A is wrong because port 443 is used for HTTPS/management, not Direct Routing SIP signaling; the Teams signaling path uses SIP TLS, not port 443.
  • C is wrong because TLS 1.2 is a requirement for Direct Routing - having it enabled is correct, not a problem.
  • D is wrong because missing Phone System licenses is a user provisioning issue that would prevent users from being voice-enabled, but it would not generate a network-level warning on the SBC.

Memory tip: Think "two-way street" - Teams must reach the SBC (inbound signaling port) and the SBC must reach Teams. An SBC warning about failed connections almost always points to a firewall blocking inbound SIP traffic to the SBC, not outbound issues from the customer network.

Topics

#Direct Routing#SBC#Firewall#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full MS-720 Practice