In this section:

Overview

The SBC Edge is certified to offer Microsoft Teams Direct Routing services, and used to connect any Teams client to:

  • A PSTN trunk, whether based on TDM (e.g. PRI, BRI, etc.), CAS, or SIP
  • 3rd-party, non-Teams-certified SIP/TDM based PBXs, analog devices, and SIP clients

These instructions detail how to connect the SBC Edge (SBC 1000/2000 and SBC SWe Lite) for Enterprise's migration from Skype for Business Cloud Connector Edition with Phone System in Office 365 (Cloud PBX) to Microsoft Phone System (Teams).

The Cloud Connector Edition (CCE) application may be physically hosted within the Ribbon SBC (SBC 1000 or SBC 2000 Cloud Link device) or within an external server. These instructions apply to both CCE deployment scenarios.

Network Topology - Skype for Business Cloud Connector Edition (CCE) with Phone System in Office 365 (Cloud PBX) Migrates to Microsoft Phone System (Teams) Deployment 

An enterprise may choose to deploy Microsoft Phone System services (Teams Direct Routing) to clients presently receiving Skype for Business Cloud Connector Edition (CCE) with Phone System in Office 365 (Cloud PBX). The instructions below detail how to migrate services from Cloud Connector Edition (CCE) to Microsoft Phone System (Teams Direct Routing) services. 

In the following example, it is assumed a Ribbon SBC Edge device qualified for Skype for Business is already deployed on the customer premises.


Before Migration - Services from Skype for Business CCE (Cloud PBX)


Enterprise with Skype for Business Online - Before Teams Direct Routing Migration


 After Migration - Services from Microsoft Phone System (Teams)


Enterprise with Skype for Business Online - After Teams Direct Routing Migration


Step 1: Install SBC Edge

These instructions assume the SBC Edge product (SBC SWe Lite, SBC 1000/2000) is installed and running. If the product is not installed, refer to the links below.

Step 2: Review Prerequisites for Microsoft Teams Direct Routing

If you plan a Big Bang migration, some Prerequisites (such as Public IP, FQDN, and Certificates) are unnecessary if existing CCE resources are being re-used.


Microsoft Teams Direct Routing Configuration

Consult the Microsoft documentation for detailed information on Direct Routing interface configuration guidelines, including the RFC standards and the syntax of SIP messages.

SBC Edge Software

Ensure you are running the latest version of SBC software:

Obtain IP Address and FQDN

Requirements for configuring the SBC Edge in support of Teams Direct Routing include:

SBC Edge Requirements

RequirementHow it is Used

Public IP address of NAT device (must be Static)*

Private IP address of the SBC

Required for SBC Behind the NAT deployment.

Public IP address of SBCRequired for SBC with Public IP deployment.
Public FQDN The Public FQDN must point to the Public IP Address.

*NAT translates a public IP address to a Private IP address.


Domain Name

For the SBC Edge to pair with Microsoft Teams, the SBC FQDN domain name must match a name registered in both the Domains and DomainUrlMap fields of the Tenant. Verify the correct domain name is configured for the Tenant as follows:

  1. On the Microsoft Teams Tenant side, execute Get-CsTenant.
  2. Review the output.
  3. Verify that the Domain Name configured is listed in the Domains and DomainUrlMap attributes for the Tenant. If the Domain Name is incorrect or missing, the SBC will not pair with Microsoft Teams.

Users may be from any SIP domain registered for the tenant. For example, you can configure user user@SonusMS01.com with the SBC FQDN name sbc1.hybridvoice.org, as long as both names are registered for the tenant.

Domain Name Examples

Domain Name*Use for SBC FQDN?FQDN Names - Examples
SonusMS01.com(tick)

Valid names:

  • aepsite6.SonusMS01.com

hybridvoice.org

(tick)

Valid names:

  • sbc1. hybridvoice.org
  • ussbcs15. hybridvoice.org
  • europe. hybridvoice.org

Non-Valid name:

sbc1.europe.hybridvoice.org (requires registering domain name europe. hybridvoice.org in “Domains” first)

*Do not use the *.onmicrosoft.com tenant for the domain name.

Configure Domain Names - Example

 

Obtain Certificate

Public Certificate

The Certificate must be issued by one of the supported certification authorities (CAs). Wildcard certificates are supported.

Configure and Generate Certificates on the SBC

Microsoft Teams Direct Routing allows only TLS connections from the SBC for SIP traffic with a certificate signed by one of the trusted certification authorities.

Request a certificate for the SBC External interface and configure it based on the example using GlobalSign as follows:

  • Generate a Certificate Signing Request (CSR) and obtain the certificate from a supported Certification Authority.
  • Import the Public CA Root/Intermediate Certificate on the SBC.
  • Import the Microsoft CA Certificate on the SBC.
  • Import the SBC Certificate.

The certificate is obtained through the Certificate Signing Request (instructions below). The Trusted Root and Intermediary Signing Certificates are obtained from your certification authority.

Step 1: Generate a Certificate Signing Request and obtain the certificate from a supported Certification Authority (CA)

Many CA's do not support a private key with a length of 1024 bits. Validate with your CA requirements and select the appropriate length of the key.

  1. Access the WebUI.
  2. Access Settings > Security > SBC Certificates.
  3. Click Generate SBC Edge CSR.

  4. Enter data in the required fields.

  5. Click OK. After the Certificate Signing request finishes generating, copy the result to the clipboard.

    Generate Certificate Signing Request

  6. Use the generated CSR text from the clipboard to obtain the certificate.

Step 2: Deploy the SBC and Root/Intermediate Certificates on the SBC

After receiving the certificates from the certification authority, install the SBC Certificate and Root/Intermediate Certificates as follows:

  1. Obtain Trusted Root and Intermediary signing certificates from your certification authority.
  2. Access the WebUI.
  3. To install Trusted Root Certificates, click Settings > Security > SBC Certificates > Trusted Root Certificates.
  4. Click Import and select the trusted root certificates.
  5. To install the SBC certificate, open Settings > Security > SBC Certificates > SBC Primary Certificate.
  6. Validate the certificate is installed correctly.

    Validate Certificate

  7. Click Import  and select X.509 Signed Certificate.
  8. Validate the certificate is installed correctly.

    Validate Certificate

  9. To install the Baltimore CyberTrust Root Certificate, click Settings > Security > SBC Certificates > Trusted Root Certificates.
  10. Click Import and select Baltimore CyberTrust Root Certificate.

  11. Validate the certificate is installed correctly.



For certificate-related errors, refer to Common Troubleshooting Issues with Certificates in SBC Edge.

Firewall Rules

Ribbon recommends the deployment of the SBC Edge product behind a firewall, within the DMZ, regardless of the assignment of a public IP to the SBC in question. Refer to SBC Edge Security Hardening Checklist for more information about the SBC and firewalls.

This section lists the ports, protocols and services for firewalls that are in the path of the SBC connecting to Teams Direct Routing.

Basic Firewall Rules for All Call Flows

Inbound Public (Internet to SBC)

SIP TLS: TCP 5061*

Media for SBC 1000: UDP 16384-17584**

Media for SBC 2000: UDP 16384-19384*

Media for SBC SWe Lite: UDP 16384-21384

Outbound Public (SBC to Internet)

DNS: TCP 53

DNS: UDP 53

NTP: UDP 123

SIP TLS: TCP 5061

Media: UDP 49152-53247

Public Access Information

The tables below represent ACL (Access Control List) examples that protect the SBC Edge. When using Easy Configuration Teams related wizards in an Enterprise deployment, these attributes are automatically provisioned. If you are manually configuring the SBC Edge as part of a Microsoft Teams Direct Routing migration scenario (for example Skype for Business or CCE), you must manually configure these ports. For details on ACLs, refer to Creating and Modifying Rules for IPv6 Access Control Lists.

Public Access In - Requirements

Description

Protocol

Action

Src IP Address

Src Port

Dest IP Address

Dest Port

Outbound SIP Reply

TCP

Allow

0.0.0.0/0

5061

SBC/32

1024-65535

Inbound SIP Request

TCP

Allow

0.0.0.0/0

1024-65535

SBC/32

5061*

Inbound Media Helper

UDP

Allow

52.112.0.0/14

52.120.0.0/14

49152-53247

SBC/32

16384-17584**

Deny All

Any

Deny

0.0.0.0/0


0.0.0.0/0


Public Access Out - Requirements

Description

Protocol

Action

Src IP Address

Src Port

Dest IP Address

Dest Port

Outbound DNS Request

TCP

Allow

SBC/32

0-65535

0.0.0.0/0

53

Outbound DNS Request

UDP

Allow

SBC/32

0-65535

0.0.0.0/0

53

Outbound NTP Request

UDP

Allow

SBC/32

0-65535

0.0.0.0/0

123

Outbound SIP Request

TCP

Allow

SBC/32

0-65535

0.0.0.0/0

5061

Inbound SIP Reply

TCP

Allow

SBC/32

5061*

0.0.0.0/0

1024-65535

Outbound Media Helper

UDP

Allow

SBC/32

16384-17584**

52.112.0.0/14

52.120.0.0/14

49152-53247

Deny All

Any

Deny

0.0.0.0/0


0.0.0.0/0


* Define in Tenant configuration

** SBC SWe Lite does not require this rule to be created since Media ports are opened as needed. This rule is required only for SBC 1000, SBC 2000 and then depends of the Media Port paired configured in the SBC.

Firewall Rules for the SBC with Media Bypass

Apply the following firewall rules below:

The Teams Client IP address cannot be predicted. As a result, allow Any IP (0.0.0.0/0).

Inbound Public (Internet to SBC) 

Media for SBC 1000: UDP 17586-21186**

Media for SBC 2000: UDP 19386-28386**

Outbound Public (SBC to Internet)

Media: UDP 50000-50019

If the device that handles the NAT between the Teams Client and SBC Public IP is performing PAT (Port Address Translation), verify that this device has the source port range of the Teams Client media or open all the ports from 1024 to 65535.

For SBC behind NAT, the firewall should allow access between the firewall IP and the NAT device's IP.

For SBC not using NAT, there must be access between the firewall and the SBC's Public IP.

Public Access

The tables below represent ACL (Access Control List) examples that protect the SBC Edge; these ACL attributes are automatically provisioned if the Teams-related Easy Configuration wizards are used (applies to the greenfield deployment scenario only).

Public Access In - Requirements (Media Bypass Scenario)

Description

Protocol

Action

Src IP Address

Src Port

Dest IP Address

Dest Port

Inbound Media Bypass Helper

UDP

Allow

0.0.0.0/0

1024-65535

SBC/32

16384-21186**

Public Access Out - Requirements (Media Bypass Scenario)

Description

Protocol

Action

Src IP Address

Src Port

Dest IP Address

Dest Port

Outbound Media Bypass Helper

UDP

Allow

SBC/32

16384-21186**

0.0.0.0/0

1024-65535

* Define in Tenant configuration

** SBC SWe Lite does not require this rule to be created since Media ports are opened as needed. This rule is required only for SBC 1000, SBC 2000 and then depends of the Media Port paired configured in the SBC.

Step 3: Configure Direct Routing from Cloud Connector Edition (CCE)

Calls from the PTSN to an Office 365 user can be sent via Teams Direct Routing before the user is moved to Teams. Calls will go via Teams Direct Routing and reach the Skype client.

Before configuring the Tenant, wait at least ten minutes before the call Tab appears on the Team client.

Configure Tenant

These instructions configure the Tenant to connect  (pair) the SBC to the Microsoft Direct Routing Interface.

  1. Access PowerShell. Refer to the PowerShell documentation.
  2. Connect to the Tenant via Powershell.
  3. Configure Microsoft Phone system Voice routing. As part of this process, use the following command to create an Online PSTN Gateway that points to the SBC:

    New-CsOnlinePSTNGateway -Fqdn <SBC Public FQDN> -SipSignallingPort <SBC SIP Port> -MaxConcurrentSessions <Max Concurrent Session which SBC capable handling> -Enabled $true
  4. Configure Teams usage for the user:

    #### USER CCE -> Teams
    Get-CsOnlineUser -Identity user1@domain.com | Select-Object -Property UserPrincipalName,EnterpriseVoiceEnabled,HostedVoiceMail,OnPremLineURI,TeamsInteropPolicy,TeamsCallingPolicy,OnlineVoiceRoutingPolicy 
    Grant-CsVoicePolicy -PolicyName "" -Identity user1@domain.com 
    Set-CsUserPstnSettings -HybridPSTNSite "" -Identity user1@domain.com 
    Grant-CsTeamsUpgradePolicy -PolicyName UpgradeToTeams -Identity user1@domain.com
    Grant-CsTeamsCallingPolicy -PolicyName AllowCalling -Identity user1@domain.com 
    Grant-CsOnlineVoiceRoutingPolicy -PolicyName "GeneralVRP" -Identity user1@domain.com

    This can be reverted at any time with the following command:

    #### USER Teams -> CCE 
    Grant-CsTeamsUpgradePolicy -PolicyName SfBOnly  -Identity user1@domain.com
    Grant-CsTeamsCallingPolicy -PolicyName "" -Identity user1@domain.com 
    Grant-CsOnlineVoiceRoutingPolicy -PolicyName "" -Identity user1@domain.com 
    Grant-CsVoicePolicy -PolicyName Tag:HybridVoice -Identity user1@domain.com 
    Set-CsUserPstnSettings -HybridPSTNSite aepsite1 -Identity user1@domain.com

    Wait at least ten minutes before the call is sent to the Skype client.

Step 4: Configure TCP and TLS between SBC and CCE

This section provides details on how to configure certificates for TCP and TLS between the SBC and Cloud Connector Edition (CCE).

Configuration Notes
  • The new certificate is required only if you choose not to use the wildcard certificate available on the Cloud Connector.
  • Calls from the PSTN to an Office 365 user can be sent via Teams Direct Routing before the user is moved to Teams. Calls will go via Teams Direct Routing and reach the Skype Client.

Using TCP between SBC and CCE

Follow instructions posted below for basic Teams configuration (Step 5).

Using TLS between SBC and CCE

 There are two types of migration from CCE To Microsoft Teams to Direct Routing:

  • Big Bang Migration. Resources are re-assigned from the CCE to Direct routing. After this migration, CCE functionality is no longer available. An Enterprise may choose a big bang migration to optimize costs associated with the migration.
  • Smooth Migration. Resources are not re-assigned from the CCE to Direct Routing. After this migration, CCE functionality continues to remain available for select clients. Enterprises may choose a smooth migration when some level of Direct Routing testing is still required prior to CCE shutdown.
Caution

One TLS port can be attached to only one TLS profile. If your CCE deployment uses TLS 5061 as the Federated port, you must modify this Federated port to use a port other than 5061. To modify the Federated port, you must update the Primary SBC Transport Protocol of the CCE topology and the Federated port of the CCE signaling group.

If you cannot modify your CCE topology, you can modify the port that Microsoft Teams Direct Routing uses. Make sure you update the Firewall, ACL, and Federated port of the Teams Signaling Group and Online PSTN Gateway.

  1. Depending on the migration type, load the Root Public CA, the Public certificate, and the private key on SBC as follows:

For a "big bang" migration:

    1. Access the WebUI. Refer to Logging into the SBC Edge.
    2. Click on the Tasks tab.
    3. Export the certificate and private key from CCE via Tasks > Office 365 Cloud Connector Edition > Setup > CCE Public Certificate > Export on PKCS12 format.
    4. From the left side menu, import the file via Certificates > Trusted CAs > Import Trusted CA certificate.

    5. From the left side menu, import the file via Certificates > SBC Primary Certificate > Import > PKCS12 certificate and key.

For a "smooth" migration:

    1. Access the WebUI. Refer to Logging into the SBC Edge.
    2. Click on the Tasks tab.
    3. From the left side menu, import the CA certificate via SBC Easy Setup > Certificates >Trusted CAs > Import Trusted CA certificate.

    4. From the left side menu, import the new certificate via Certificates > SBC Primary Certificate > Import > PKCS12 certificate and key.

  1. Exchange the root certificate between the SBC and CCE via Tasks > Office 365 > SBC Easy Setup > CCE Private Certificate > Synchronize CCE/SBC CA Certificate. For details, refer to Managing Cloud Connector Edition Private Certificates.

    For
    details on certificates, refer to: Importing an SBC Edge Primary Certificate and Managing Trusted CA Certificates.
    Do not modify the node Hostname, but use the public name of SBC in the SIP profile.

Step 5: Configure SBC Edge for Microsoft Teams Direct Routing


These instructions assume the SBC Edge is installed and running, and is connected to the WebUI.

For the purposes of this documentation, the screens displayed are for an SBC 1000/2000; the interface configuration may vary slightly for the SBC SWe Lite. If configuration is not specified for a field, use the default value.

Access the SBC Edge WebUI

Access the WebUI. Refer to Logging into the SBC Edge.

Configure Host Information and DNS

The Host Information and DNS configuration contains system information that is used by the SBC Edge, including host, domain, and NTP server information.

  1. In the WebUI, click the Settings tab.
  2. In the left navigation page, access System > Node-Level Settings. The Node-Level Settings page is displayed.

  3. Configure the NTP and DNS Servers with network-specific data.

  4. Leave all other parameters as default.

  5. Click Apply.

    TLS Configuration - Example Values

    ParameterExample Value
    Host Nameaepsite6
    Domain NameSonusMS01.com
    Use NTPYes
    NTP ServerSpecifies the FQDN, IPv4, or IPv6 address of the NTP server. If the host name is supplied, the SBC uses the DNS to connect to the NTP server.
    Use Primary DNSYes
    Primary Server IPXXX.XXX.XX.XXX

    Node-level Settings - Example

Configure Logical Interface

The SBC Edge supports system-supported Logical Interfaces, which are used to hold the IP address for each Ethernet port. One of these logical interfaces is assigned an IP address for transporting the VoIP media packets (i.e., RTP, SRTP) and protocol packets (i.e, SIP, RTCP, TLS). In this example, Ethernet 1 is configured for transporting packets for the Microsoft Teams Direct Routing connection.

Ensure the IP Routing Table contains the same information as in the network topology.

  1. In the WebUI, click the Settings tab.
  2. In the left navigation pane, go to Node Interfaces > Logical Interfaces.

  3. Configure the parameters as shown below (example values are shown in the table; configure as per your network requirements). For details on field descriptions, refer to Configuring and Modifying Logical Interfaces.

  4. Leave all other parameters as default.
  5. Click Apply.

    Logical Interfaces Configuration - Example Values

    ParameterExample Value
    AliasTo Microsoft Phone 5

    Description

    Interface to Interconnect with Microsoft Phone System

    Admin Interface

    Enable

    IP Assign Method

    Static

    Primary Address

    <Public IP of your SBC> (in the example 192.168.211.80)

    Primary Netmask

    <Mask of Public Interface of your SBC> (in the example 255.255.255.0)

    Logical Interfaces - Example

Use Easy Config Wizard

Easy Config Wizard can be used to create all the resource required for Microsoft Teams Direct Routing.

Step 1: Select Microsoft Teams Connection

  1. In the WebUI, click the Tasks tab.
  2. In the left navigation panel, go to SBC Easy Setup > Easy Config Wizard.
  3. From the Application drop down list, select Microsoft Teams.

  4. Configure per the field definitions below and click Next.

    Configure Microsoft Teams Connection

    Configure Scenario Parameters - Field Definitions

    FieldDescription
    ApplicationConfiguration template used: Microsoft Teams.
    Scenario DescriptionName to describe the setup.
    Telephone CountryCountry in which Microsoft Teams is setup.
    SIP SessionsNumber of simultaneous SIP Sessions. Valid entry: 1 - 960.
    Teams ConnectionThe Teams connection type used for the network. Valid selections:
    • Teams Direct Routing
    • Teams Downstream SBC

Step 2: Configure Microsoft Teams for Endpoint

Easy Configuration Step 2 includes configuration for the Microsoft Teams endpoint. The configuration items displayed in Step 2 depends on the connection type for the Microsoft Teams leg you configured in Step 1. See below for each type. 

  1. Configure the connection type information.
  2. Click Next.

Step 2 Example Screen


The fields below are displayed if you select Teams Direct Routing from the Teams Connection drop down list in Step 1. 


Configure Teams Direct Routing

FieldDescription

Teams Connection Type - Standalone Direction Connection

Signaling/Media Source IPClick the drop-down arrow to select the external (Internet-facing) IP address of the Microsoft Teams Direct Routing server that handles routing of messages for signaling and media.
Outbound NAT Traversal

Allows the SBC to be placed behind a NAT device, and uses the IP of the NAT device for all outgoing messages. If this field is set to Enable, the Public IP address field configuration is required. Valid selections:

Enable: Network Address Translation is used for the NAT device's Public IP address.

Disable: Network Address Translation address translation is not used.

NOTE: This field is required when the SBC interface has a private IP and the NAT device is using a public IP. For details on configuring an SBC behind the NAT, refer to Configuring the SBC Edge for NAT Traversal.

Apply ACL

Specifies whether an ACL (Access Control List) is applied to the Microsoft Teams connection. An ACL provides security to an SBC using a Public IP.

Valid selection:

True: Applies the ACL.

False: Does not apply the ACL. 

For details on configuring an ACL to be applied to an SBC, refer to Managing Access Control Lists.

ProtocolHard-coded value for protocol used with federated FQDN: TLS.
Server Port NumberHard-coded value for the port used for TLS: 5061.
Listening Port NumberPort number used for sending and receiving SIP messages between the SBC and the Border Element Server.

Step 3: Summary

Easy Configuration Step 3 includes a summary of the information configured in Step 1 and Step 3.

Review the information and click Finish.

See below for an example:

Step 3 Example Screen


Create Transformation Table and Entries

This Transformation Table contains a list of call routes that include routing configuration for calls from Microsoft Teams and SIP Trunk. Two Transformation tables are required:

  • For Calls from Microsoft Teams to SIP Trunk
  • For Calls from SBC's SIP Trunk to Microsoft Teams

Calls From Microsoft Teams to SBC's SIP Trunk

This Transformation Table contains a list of call routes that include routing configuration for calls from Microsoft Teams to SBC's SIP Trunk.

  1. In the WebUI, click the Settings tab.
  2. In the left navigation page, access Call Routing > Transformation
  3. Click the ( ) icon at the top left corner to add a new Transformation Table.

  4. For Description, enter From Microsoft Teams
  5. Click OK.

    Create Transformation Table

  6. In the left navigation panel, select the new table:  Transformation > From Microsoft Teams: Passthrough.

  7. Click the Create ( ) icon.

  8. Configure the parameters as shown below. Leave the default values for all other parameters.
  9. Click OK.

    Transformation Entries - Example Values

    Parameter

    Value

    DescriptionFrom Microsoft Teams: Passthrough
    Match TypeMandatory (Must Match)
    Input FieldType: Called Address/Number
    Value: (.*)
    Output FieldType: Called Address Number
    Value: \1

    Transformation Entry - Example

     

    Transformation Table - Entry Added

Calls From SBC's SIP Trunk to Microsoft Teams

This Transformation Table contains a list of call routes that include routing configuration for calls from the SBC's SIP Trunk to Microsoft Teams.

  1. In the WebUI, click the Settings tab.
  2. In the left navigation page, access Call Routing> Transformation
  3. Click the ( ) icon at the top left corner to add a new Transformation Table.

  4. For Description, enter From SIP Trunk.
  5. Click OK.

    Create Transformation Table

  6. In the left navigation panel, select the new table:  Transformation > From SIP Trunk to Microsoft Teams: Passthrough.

  7. Click the Create ( ) icon.

  8. Configure the parameters as shown below. Leave the default values for all other parameters.
  9. Click OK.

    Transformation Entries - Example Values

    Parameter

    Value

    Description

    From SIP Trunk: Passthrough

    Match Type

    Mandatory (Must Match)

    Input Field

    Type: Called Address/Number

    Value: (.*)

    Output Field

    Type: Called Address Number

    Value: \1

    Transformation Table Entry

    Transformation Table - Entry Added

Create Call Routing entries

Two Call Routing Tables need to be modified for transporting calls between the SBC's SIP Trunk and Microsoft Teams:

  • Call Route - Calls from Microsoft Teams to SBC's SIP Trunk
  • Call Route - Calls from the SBC's SIP Trunk to Microsoft Teams

From Microsoft Teams to SBC's SIP Trunk

This Call Routing Table routes calls from Microsoft Teams.

  1. In the WebUI, click the Settings tab.
  2. From the left navigation pane, click on the Call Routing > Call Routing table.

  3. Select From Microsoft Teams (the entry you just created).

  4. Click the ().
  5. Configure the parameters as shown below. Leave all other parameters as default.

  6. Click OK.

    Call Routing Table Configuration - Example

    Parameter

    Value

    Description

    To SIP Trunk (Passthrough)

    Number/Name Transformation Table

    From Microsoft Teams: Passthrough (select Transformation Table you created above)

    Destination Signaling Groups

    Choose the Signaling Group of a local equipment.

    Call Routing Table - Example

From SBC's SIP Trunk to Microsoft Teams

This Call Routing Table routes calls from the SBC's SIP Trunk and sent to Microsoft Teams.

To add and configure a new Call Routing Table:

  1. In the WebUI, click the Settings tab.
  2. From the left navigation pane, click on the Call Routing > Call Routing table.

  3. Select From SIP Trunk, this table already contains an entry to route the calls to CCE.

  4. Select the existing entry where First Signaling Group is CCE
  5. Set the Admin State to Disabled
  6. Click OK.
  7. From the left navigation pane, click on the Call Routing > Call Routing table.

  8. Select From SIP Trunk, this table already contains an entry to route the calls to CCE.

  9. Click the ().
  10. Configure the parameters as shown below. Leave all other parameters as default.

  11. Click OK.

    Call Routing Table Configuration - Example

    Parameter

    Value

    Description

    To Microsoft Teams (Passthrough)

    Number/Name Transformation Table

    From SIP Trunk to Microsoft Teams: Passthrough (select Transformation Table you created above)

    Destination Signaling Groups

    Choose the Signaling Group for Microsoft Teams Direct Routing

    Call Routing Table - Example


Step 6: Configure SBC Edge when Microsoft Teams is in Media Bypass Mode and Non-Media Bypass Mode

Non-Media Bypass vs. Media Bypass Deployment


Non-Media Bypass

Non-Media Bypass is Microsoft Teams Direct Routing related deployment where all media flows between Teams clients in the enterprise and the SBC transit the Teams Phone System based in the Azure cloud.

Teams Direct Routing - Without Media Bypass



Media Bypass

Media Bypass is a Microsoft Teams Direct Routing deployment where all media flows between Teams clients in the enterprise connect directly to the SBC without transiting the Teams Phone System.

If Microsoft Teams is in Media Bypass or Non-Media Bypass mode, you must configure the SBC Edge as detailed in the section below.

For Media Bypass, the following is supported:

  • Deployment on a Public IP address
  • Deployment behind NAT

Configure Signaling Group 

Before configuring Outbound NAT Traversal, obtain the Public IP address for your network (the Public IP address specified in the screen graphic is an example only); configuration for NAT is required only if deployment is behind NAT.

  1. In the WebUI, click the Settings tab.
  2. In the left navigation page, access Signaling Groups
  3. From the Create Signaling Group drop down box, select SIP Signaling Group.

  4. Configure the parameters as shown below. Leave the default values for all other parameters.

  5. Click OK.

    Signaling Group Configuration - Example Values

    Parameter

    Value

    RTCP MultiplexingEnable
    ICE SupportEnabled
    ICE ModeLite
    Outbound NAT Traversal*Static NAT
    NAT Public IP (Signaling/Media)*Public Address for the NAT device assigned on the media port for your network
    Static NAT InboundDisabled 

    *Outbound NAT Traversal and the NAT Public IP is required when the SBC is behind a NAT (the public IP address of the NAT device is required when the SBC has a Private IP).


    The peer endpoint must support the a=rtcp-mux exchange in order for the RTP and RTCP ports to be multiplexed into one data port.

    SIP Signaling Group - Example

Step 7: Confirm the Configuration

Validate SIP Option

  1. Access the WebUI. Refer to Logging into the SBC Edge.
  2. In the left navigation pane, access Signaling Groups.
  3. For the signaling group configured for Microsoft Teams Direct Routing, click Counters.
  4. Confirm the number of Incoming and Outgoing SIP Options.
  5. Confirm the number of Incoming and Outgoing 2xx responses.


Incoming and Outgoing Counters



Step 8: Place a Test Call

Place a test call as follows:

  1. Access the WebUI. Refer to Logging into the SBC Edge.

  2. In the WebUI, click the Diagnostics tab.

  3. In the left navigation pane, click Test a Call.

  4. Configure the parameters as shown below.

  5. Click OK. 

    Place a Test Call - Parameters

    Parameter

    Value

    Destination Number

    Number assigned to a Teams user.

    Origination/Calling Number

    Number assigned to a Local user.

    Call Routing Table

    The routing table that handles the call from Microsoft Teams.

     

    Test a Call - Configuration

    Place a Test Call - Example

     

The test call is now complete. For troubleshooting steps, refer to Best Practice - Troubleshoot Issues with Microsoft Teams Direct Routing.