MS-721 · Question #201
You are deploying Direct Routing by using a certified Session Border Controller (SBC). The FQDN of the SBC is sbc1.contoso.com. You use signaling port 5067. You cannot place calls and receive an error
The correct answer is D. The firewall blocks traffic on port 5067.. Direct Routing requires specific firewall ports to be open for SIP signaling between the SBC and Microsoft 365. Blocking port 5067 prevents SIP traffic from reaching the Microsoft infrastructure, causing call failures visible in the Teams admin center.
Question
Exhibit
Options
- AThe SIP options are disabled.
- BThe failover timer is set to 0 seconds.
- CLicenses are not assigned to the contoso.com domain.
- DThe firewall blocks traffic on port 5067.
How the community answered
(34 responses)- A15% (5)
- B6% (2)
- C9% (3)
- D71% (24)
Why each option
Direct Routing requires specific firewall ports to be open for SIP signaling between the SBC and Microsoft 365. Blocking port 5067 prevents SIP traffic from reaching the Microsoft infrastructure, causing call failures visible in the Teams admin center.
Disabled SIP options would affect the health monitoring of the SBC but would not fully block call signaling in a way consistent with a firewall-blocked port error.
A failover timer of 0 seconds would cause immediate route failover to a backup trunk, not a complete inability to place calls.
Licenses in Microsoft 365 are assigned to user accounts, not to domains; the contoso.com domain itself does not require a license assignment for Direct Routing to function.
Direct Routing SIP signaling between the SBC and Microsoft 365 must traverse the firewall on the configured port, in this case 5067. If the firewall blocks this port, the SBC cannot establish a SIP trunk with Microsoft's infrastructure, resulting in an error state shown in the Teams admin center. All inbound and outbound SIP traffic on the designated signaling port must be explicitly permitted.
Concept tested: Direct Routing firewall port requirements for SBC
Source: https://learn.microsoft.com/en-us/microsoftteams/direct-routing-plan#firewall-requirements-for-direct-routing
Topics
Community Discussion
No community discussion yet for this question.
