nerdexam
Microsoft

MS-721 · Question #241

You are deploying Direct Routing by using a certified Session Border Controller (SBC). The FQDN of the SBC is sbc1.contoso.com. You use signaling port 5067. You cannot place calls and receive an error

The correct answer is C. The Digicert root certificate is missing on the SBC.. When deploying Direct Routing, an error preventing calls, especially on a specific signaling port like 5067, often indicates a problem with the TLS connection establishment. The absence of a trusted root certificate on the SBC would cause TLS handshake failures, leading to commun

Maintain and troubleshoot collaboration communications systems

Question

You are deploying Direct Routing by using a certified Session Border Controller (SBC). The FQDN of the SBC is sbc1.contoso.com. You use signaling port 5067. You cannot place calls and receive an error message in the Microsoft Teams admin center as shown in the following exhibit. What is a possible cause of the issue?

Exhibit

MS-721 question #241 exhibit

Options

  • AThe SIP options are disabled.
  • BThe Forward P-Asserted Identify (PAI) header is disabled.
  • CThe Digicert root certificate is missing on the SBC.
  • DLocation-Based Routing is enabled for the SBC.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    80% (16)
  • D
    10% (2)

Why each option

When deploying Direct Routing, an error preventing calls, especially on a specific signaling port like 5067, often indicates a problem with the TLS connection establishment. The absence of a trusted root certificate on the SBC would cause TLS handshake failures, leading to communication issues.

AThe SIP options are disabled.

SIP options being disabled would typically prevent the SBC from registering its availability with Teams, but a signaling port error usually points to a deeper connection or certificate issue.

BThe Forward P-Asserted Identify (PAI) header is disabled.

The Forward P-Asserted Identity (PAI) header is related to caller ID and identity assertion, not the fundamental ability to establish calls due to a signaling port or TLS error.

CThe Digicert root certificate is missing on the SBC.Correct

Direct Routing uses TLS for signaling communication, typically on port 5067. If the SBC is missing the necessary trusted root certificate, such as a Digicert root, it will fail to establish a secure TLS connection with Microsoft 365, preventing calls.

DLocation-Based Routing is enabled for the SBC.

Location-Based Routing being enabled for the SBC would restrict call routing based on network location, but it would not prevent calls due to a signaling port or TLS certificate issue.

Concept tested: Direct Routing SBC TLS certificate requirements

Source: https://learn.microsoft.com/en-us/microsoftteams/direct-routing-certificate-requirements

Topics

#Direct Routing#SBC configuration#TLS certificates#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full MS-721 Practice