MS-721 · Question #121
You have a Microsoft Teams Phone deployment. You are deploying Direct Routing. All users have a SIP URI in the format of [email protected]. The Session Border Controller (SBC) is named sbc.voice.contos
The correct answer is C. The certificate does not match the FQDN of the SBC.. In Direct Routing, the SBC must present a TLS certificate whose Subject Name (CN) or Subject Alternative Name (SAN) exactly matches the FQDN of the SBC as configured in Teams. In this scenario the SBC is named sbc.voice.contoso.com. If the certificate installed on the SBC was iss
Question
Options
- AThe tenant is missing a vanity domain of voice.contoso.com.
- BThe firewall blocks outbound traffic on port 443 to Microsoft Teams.
- CThe certificate does not match the FQDN of the SBC.
- DMedia bypass is disabled on the SBC.
How the community answered
(20 responses)- A5% (1)
- B5% (1)
- C75% (15)
- D15% (3)
Explanation
In Direct Routing, the SBC must present a TLS certificate whose Subject Name (CN) or Subject Alternative Name (SAN) exactly matches the FQDN of the SBC as configured in Teams. In this scenario the SBC is named sbc.voice.contoso.com. If the certificate installed on the SBC was issued for a different FQDN (for example, sbc.contoso.com or *.contoso.com without the voice subdomain), the TLS mutual authentication will fail and generate a warning. A missing vanity domain (A) would cause a different type of routing error. Port 443 blockage (B) would disrupt HTTPS-level communication. Media bypass being disabled (D) affects media path but not signaling-level TLS warnings.
Topics
Community Discussion
No community discussion yet for this question.