{"id":2224,"date":"2021-01-31T16:36:43","date_gmt":"2021-01-31T16:36:43","guid":{"rendered":"https:\/\/modern-workplace.uk\/?p=2224"},"modified":"2021-01-31T20:42:00","modified_gmt":"2021-01-31T20:42:00","slug":"teams-virtual-sbc-closing-azure-network-ports-warnings-for-azureloadbalancer-and-virtualnetwork-2-2-2-2","status":"publish","type":"post","link":"https:\/\/modern-workplace.uk\/?p=2224","title":{"rendered":"Teams &#8211; Direct Routing &#8211; The impact of Media Bypass on remote working (home working) users"},"content":{"rendered":"\n<p class=\"has-normal-font-size\"><strong>Direct Routing<\/strong> with <strong>Media Bypass<\/strong> has been available for almost two years now and its benefits in different scenarios are clear.<\/p>\n\n\n\n<p class=\"has-normal-font-size\">For example, in a corporate environment with SBCs deployed inside the internal network, there are positive results when the users are connecting from the company&#8217;s offices.<\/p>\n\n\n\n<p class=\"has-normal-font-size\">However, with the existing situation pushing companies to remote work (and this will probably be still the case for a few months at least), it is more relevant than ever to optimise the remote users\u2019 connectivity (especially the Media traffic) to Teams<\/p>\n\n\n\n<p class=\"has-normal-font-size\">Whilst Signaling traffic always flows via the Microsoft Cloud (and it does not contribute much to the overall network usage), Media traffic is managed really in a different way if we use Direct Routing with or without Media Bypass (and the Media traffic is the one that uses more bandwidth, so important to optimise)<\/p>\n\n\n\n<p class=\"has-normal-font-size\">There are two components in the Microsoft Cloud that can be in the path of media traffic: <strong>Media Processors (MPs)<\/strong> and <strong>Transport Relays (TRs)<\/strong>. Depending on our configuration, they could be involved in the path for media traffic.<\/p>\n\n\n\n<p class=\"has-normal-font-size\">I am not going to deep dive them here, but there are some important information to understand, as stated in this Microsoft document <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/direct-routing-plan-media-bypass\" data-type=\"URL\" data-id=\"https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/direct-routing-plan-media-bypass\">https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/direct-routing-plan-media-bypass<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Schema-TR.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Schema-TR.jpg\" alt=\"\" class=\"wp-image-2225\" width=\"580\" height=\"310\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Schema-TR.jpg 940w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Schema-TR-300x161.jpg 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Schema-TR-768x412.jpg 768w\" sizes=\"auto, (max-width: 580px) 100vw, 580px\" \/><\/a><\/figure>\n\n\n\n<p class=\"has-normal-font-size\"><strong>Media Processors<\/strong>:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>will always be used in a non-bypass scenario<\/li><li>are not always available in a region (5 regions are available so far)<\/li><li>will be always used for voice applications like Auto Attendant and Call Queues<\/li><\/ol>\n\n\n\n<p class=\"has-normal-font-size\"><strong>Transport Relays<\/strong>:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>will be used only if the public IP of the SBC is not reachable<\/li><li>will always be used for scenarios with Media Bypass<\/li><li>are more extensively available in regions near to the users<\/li><\/ol>\n\n\n\n<p>As an additional information, as for conferencing, <strong><em>MPs will be always selected based on the location of the SBC, not on the location of the user<\/em> <\/strong>(Mark Vale did some testing around that some time ago <a href=\"https:\/\/commsverse.blog\/2019\/09\/20\/microsoft-teams-media-with-privacy-boundaries\/\">https:\/\/commsverse.blog\/2019\/09\/20\/microsoft-teams-media-with-privacy-boundaries\/<\/a> )<\/p>\n\n\n\n<p>So, let\u2019s outline a few scenarios, assuming that<br>\u2022 We are focusing on home-based users<br>\u2022 The users are able to connect to Office 365 and Teams directly using their local Internet connection (no VPN or split-tunnel VPN deployed)<br>\u2022 When possible, the client will use the nearest geographical public IP address for the Office 365 and Azure services<br>\u2022 The SBC is deployed in Azure (there is not a big difference if it is in your datacentre for this conversation, though)<\/p>\n\n\n\n<p class=\"has-luminous-vivid-amber-color has-text-color has-medium-font-size\"><strong>First Scenario: Direct Routing, Media Bypass, SBC with no filters on incoming IPs or ports<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/OpenSBC.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"923\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/OpenSBC-1024x923.jpg\" alt=\"\" class=\"wp-image-2226\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/OpenSBC-1024x923.jpg 1024w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/OpenSBC-300x271.jpg 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/OpenSBC-768x693.jpg 768w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/OpenSBC.jpg 1090w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p><br>\u2022 Media flow will go directly from the Teams client to the public IP of the SBC<br>\u2022 The traffic will not use the Microsoft Azure network, so there could be a lot of unmanaged hops between the client and the SBC (opposite to using the nearest access to the Azure network)<br>\u2022 There are risks about security with this solution that does not control the Internet access to the SBC services<\/p>\n\n\n\n<p class=\"has-luminous-vivid-amber-color has-text-color has-medium-font-size\"><strong>Second Scenario: Direct Routing, No Media Bypass, SBC allowing only Microsoft IPs<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/NoBypass.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"943\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/NoBypass-1024x943.jpg\" alt=\"\" class=\"wp-image-2227\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/NoBypass-1024x943.jpg 1024w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/NoBypass-300x276.jpg 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/NoBypass-768x707.jpg 768w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/NoBypass.jpg 1034w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>The client will connect to the Media Processor<\/li><li>The Media Processor used will be the one nearest to the SBC<\/li><li>The client media flow &nbsp;will not use the Microsoft Azure network, so there could be a lot of unmanaged hops between the client and the MP (opposite to using the nearest access to the Azure network)<\/li><\/ul>\n\n\n\n<p class=\"has-luminous-vivid-amber-color has-text-color has-medium-font-size\"><strong>Third Scenario: Direct Routing, Media Bypass, SBC allowing only Microsoft IPs<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Bypass.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"972\" src=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Bypass-1024x972.jpg\" alt=\"\" class=\"wp-image-2228\" srcset=\"https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Bypass-1024x972.jpg 1024w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Bypass-300x285.jpg 300w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Bypass-768x729.jpg 768w, https:\/\/modern-workplace.uk\/wp-content\/uploads\/2021\/01\/Bypass.jpg 1034w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n\n\n\n<p>\u2022 The client will connect to the Transport Relay<br>\u2022 The Transport Relay used will be the one nearest to the client<br>\u2022 The client media flow will use the Microsoft Azure network as soon as possible, granting a good quality connection<\/p>\n\n\n\n<p class=\"has-vivid-purple-color has-text-color has-medium-font-size\"><strong>Wrap Up<\/strong><\/p>\n\n\n\n<p>As you can see, the safest solution, from a quality of connection point of view, talking about users connecting from their homes, should be Direct Routing with Media Bypass (with the SBC configured to accept connectivity only from Microsoft, as for the recommended standards <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/direct-routing-plan\" data-type=\"URL\" data-id=\"https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/direct-routing-plan\">https:\/\/docs.microsoft.com\/en-us\/microsoftteams\/direct-routing-plan<\/a> )<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the existing situation that pushes companies to remote work it is more relevant than ever to optimise the remote users\u2019 connectivity (especially the Media traffic) to Teams<\/p>\n","protected":false},"author":1,"featured_media":2229,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","twitterCardType":"","cardImageID":0,"cardImage":"","cardTitle":"","cardDesc":"","cardImageAlt":"","cardPlayer":"","cardPlayerWidth":0,"cardPlayerHeight":0,"cardPlayerStream":"","cardPlayerCodec":"","footnotes":""},"categories":[765,753,752,757,690],"tags":[762,759,751,77,691,755],"class_list":["post-2224","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-765","category-microsoft365","category-microsoft-teams","category-office-365","category-skype-for-business","tag-microsoftteams","tag-microsoft-365","tag-microsoft-teams","tag-office-365","tag-skype-for-business","tag-teams"],"_links":{"self":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2224"}],"version-history":[{"count":4,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2224\/revisions"}],"predecessor-version":[{"id":2234,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/posts\/2224\/revisions\/2234"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=\/wp\/v2\/media\/2229"}],"wp:attachment":[{"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/modern-workplace.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}