Teams ports

%3CLINGO-SUB%20id%3D%22lingo-sub-3254895%22%20slang%3D%22en-US%22%3ETeams%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3254895%22%20slang%3D%22en-US%22%3E%3CP%3EHi!%3C%2FP%3E%3CP%3EWe%20are%20using%20Checkpoint%20firewall.%20UDP%20ports%203478-3481%20are%20open%20and%20using%26nbsp%3B%3CSPAN%3Eupdateable%20objects%20to%20allow%20STUN%20traffic.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThe%20question%20is%20about%20%3CSTRONG%3EUDP%3C%2FSTRONG%3E%20ports%20like%20%3CSTRONG%3E10400%3C%2FSTRONG%3E%2C%20%3CSTRONG%3E10500%3C%2FSTRONG%3E%2C%20%3CSTRONG%3E10600%3C%2FSTRONG%3E%2C%20%3CSTRONG%3E10700%3C%2FSTRONG%3E%20etc.%20We%20can't%20open%20these%20ports%20and%20still%20there%20is%20traffic%20from%20Microsoft%20that%20go%20through%20these%20and%20being%20dropped%20because%20this%20traffic%20is%20trying%20to%20talk%20directly%20with%20the%20firewall%2C%20i%20mean%20it%20is%20the%20Stealth%20rule%20.%20Check%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.pearsonitcertification.com%2Farticles%2Farticle.aspx%3Fp%3D387728%26amp%3BseqNum%3D3%23%3A~%3Atext%3DA%2520Skeleton%2520Rule%2520Base%26amp%3Btext%3DThe%2520purpose%2520of%2520the%2520stealth%2Crequire%2520access%2520to%2520the%2520firewall%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fwww.pearsonitcertification.com%2Farticles%2Farticle.aspx%3Fp%3D387728%26amp%3BseqNum%3D3%23%3A~%3Atext%3DA%2520Skeleton%2520Rule%2520Base%26amp%3Btext%3DThe%2520purpose%2520of%2520the%2520stealth%2Crequire%2520access%2520to%2520the%2520firewall%3C%2FA%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThis%20traffic%20source%20is%20from%20IP%20addresses%20ranges%20like%2052.114.%20or%2052.112%20and%20being%20droped.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3ECan%20this%20traffic%20affect%20the%20quality%20of%20Teams%20video%20or%20audio%20meetings%20because%20we%20had%20some%20people%20that%20had%20problems%20with%20that%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20can't%20find%20any%20documentation%20from%20Microsoft%20that%20talk%20about%20these%20UDP%20ports!%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3254895%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3256455%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3256455%22%20slang%3D%22en-US%22%3EThe%20assessment%20tool%20says%20%22Relay%20connectivity%20and%20Qos%20(Media%20Priority)%20check%20is%20successful%20for%20all%20relays.%22%2C%20but%20still%20many%20packets%20are%20dropped%20from%2052.112%20or%2052.114%20ip%20addresses%20that%20aim%20to%20UDP%20ports%20like%2010400%20or%2010500%20etc%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3256445%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3256445%22%20slang%3D%22en-US%22%3EI%20am%20not%20sure%20about%20those%20ports%2C%20however%2C%20the%20assessment%20tool%20will%20help%20you%20understand%20if%20you%20will%20have%20issues%20in%20your%20current%20environment%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3256129%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3256129%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F20390%22%20target%3D%22_blank%22%3E%40Andres%20Gorzelany%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20still%20can't%20find%20explanation%20to%20why%20UDP%20ports%20like%2010400%20are%20used.%20Are%20these%20ports%20needed%20to%20be%20open%20or%20not%3F%20Every%20packet%20which%20comes%20to%20these%20is%20dropped%20by%20my%20firewall!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3255499%22%20slang%3D%22en-US%22%3ERe%3A%20Teams%20ports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3255499%22%20slang%3D%22en-US%22%3EI%20recommend%20using%20the%20assessment%20tool%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D103017%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D103017%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3Einformation%20on%20how%20to%20use%20%3CA%20href%3D%22https%3A%2F%2Fwww.myteamslab.com%2F2021%2F08%2Fteams-network-assessment-tool-july-2021.html%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.myteamslab.com%2F2021%2F08%2Fteams-network-assessment-tool-july-2021.html%3C%2FA%3E%3C%2FLINGO-BODY%3E
New Contributor

Hi!

We are using Checkpoint firewall. UDP ports 3478-3481 are open and using updateable objects to allow STUN traffic.

 

The question is about UDP ports like 10400, 10500, 10600, 10700 etc. We can't open these ports and still there is traffic from Microsoft that go through these and being dropped because this traffic is trying to talk directly with the firewall, i mean it is the Stealth rule . Check 

https://www.pearsonitcertification.com/articles/article.aspx?p=387728&seqNum=3#:~:text=A%20Skeleton%....

 

This traffic source is from IP addresses ranges like 52.114. or 52.112 and being droped. 

Can this traffic affect the quality of Teams video or audio meetings because we had some people that had problems with that?

I can't find any documentation from Microsoft that talk about these UDP ports!

4 Replies

@Andres Gorzelany 

I still can't find explanation to why UDP ports like 10400 are used. Are these ports needed to be open or not? Every packet which comes to these is dropped by my firewall!

I am not sure about those ports, however, the assessment tool will help you understand if you will have issues in your current environment
The assessment tool says "Relay connectivity and Qos (Media Priority) check is successful for all relays.", but still many packets are dropped from 52.112 or 52.114 ip addresses that aim to UDP ports like 10400 or 10500 etc