Unknown Office 365 IP address

%3CLINGO-SUB%20id%3D%22lingo-sub-57307%22%20slang%3D%22en-US%22%3EUnknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-57307%22%20slang%3D%22en-US%22%3E%3CP%3EI%20saw%20at%20a%20customer%20site%20today%2C%20a%20STUN%20request%20going%20from%20the%20client%20to%2013.100.4.192.%20By%20looking%20at%20the%20src%20and%20dest%20ports%2C%20I%20would%20say%20this%20is%20a%20video%20session%20trying%20to%20establish%20a%20connection%20to%20a%20meeting.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F12452i34488ACCF34022E4%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22screenshot_2017-03-28_001.png%22%20title%3D%22screenshot_2017-03-28_001.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20IP%20address%20is%20not%20listed%20in%20any%20of%20the%20Office%20365%20IP%20ranges%2C%20so%20the%20traffic%20is%20blocked%20by%20the%20firewall.%20After%20some%20time%20the%20client%20tries%20to%20connect%20to%20a%26nbsp%3B52.112.0.0%2F14%20host%20and%20the%20RTP%20flow%20is%20established%20towards%20this%20host.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20influences%20user%20experience%20as%20the%20connection%20takes%20longer%20time%20than%20necessary.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20anyone%20know%20this%20IP%20address%20and%20which%20range%20should%20be%20allowed%20for%20this%20to%20connect%3F%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%2FKenneth%20ML%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-57307%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConferencing-Meeting%20Join%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-294823%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-294823%22%20slang%3D%22en-US%22%3E%3CP%3EThe%2013.100%20series%20are%20only%20the%20Host%20IPs.%20Not%20necessarily%20it%20needs%20to%20be%20route-able%20publicly.%26nbsp%3B%20It%20would%20by%20default%20try%20connecting%20direct%20and%20fail.%20We%20need%20to%20worry%20only%20about%20Relay%20IP%20which%20is%2052.112%20on%20most%20cases.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ea%3Dcandidate%3A1%201%20tcp-pass%202120613887%2013.100.10.217%2061560%20typ%20host%3CBR%20%2F%3Ea%3Dcandidate%3A2%201%20tcp-act%202121006591%2013.100.10.217%2062483%20typ%20host%3CBR%20%2F%3Ea%3Dcandidate%3A3%201%20tcp-pass%20174455807%2052.112.0.193%2059614%20typ%20relay%20raddr%2013.100.10.217%20rport%2061049%3CBR%20%2F%3Ea%3Dcandidate%3A4%201%20tcp-act%20174848511%2052.112.0.193%2059614%20typ%20relay%20raddr%2013.100.10.217%20rport%2061049%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-294628%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-294628%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20noticed%20the%20same%20phenomenon.%20We%20had%20a%20lot%20of%20users%20reporting%20issues%20when%20having%20Skype%20for%20Business%20calls%20with%20external%20participants%20or%20when%20having%20a%20call%20with%20multiple%20participants.%20Both%20scenario's%20connect%20to%20SfB%20online.%26nbsp%3B%3C%2FP%3E%3CP%3EInternal%20point%20to%20point%20call%20did%20not%20show%20any%20issues.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20pointed%20us%20in%20the%20direction%20of%20the%20firewall%20in%20place%20between%20our%20network%20and%20the%20Microsoft%20(SfB)%20cloud%20environment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20extensively%20going%20through%20the%20firewall%20logs%20and%20cross%20linking%20with%20the%20call%20quality%20dashboard%20now%20available%20on%20the%20Teams%20%26amp%3B%20Skype%20for%20Business%20admin%20portal%20we%20noticed%20a%20lot%20of%20drops%20by%20the%20firewall.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20investigating%20these%20drops%20we%20noticed%20a%20lot%20of%20inconsistencies%20with%20the%20documentation%20provided%20by%20Microsoft.%3C%2FP%3E%3CUL%3E%3CLI%3EHigh%20ports%20range%2050000-59999%20should%20actually%20be%2049152-65535%3C%2FLI%3E%3CLI%3EConnections%20towards%2013.100.x.x%20ranges%20(UDP3478-3481)%20-%26gt%3B%20After%20WhoIs%20lookup%20the%20subnet%20is%20actually%2013.96.0.0%2F13%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThis%20inconsistencies%20caused%20a%20lot%20of%20performance%20issues%20and%20users%20complaining%20about%20calls%20being%20dropped%2C%20content%20sharing%20issues%2C%20etc...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-58116%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-58116%22%20slang%3D%22en-US%22%3EYes%20I%20made%20a%20mistake%2C%20verify%20again%20the%20xml%20file%20was%20updated%20the%2029th%20of%20march%20%3CA%20href%3D%22https%3A%2F%2Fsupport.content.office.net%2Fen-us%2Fstatic%2FO365IPAddresses.xml%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.content.office.net%2Fen-us%2Fstatic%2FO365IPAddresses.xml%3C%2FA%3Eans%20still%20doesn't%20have%20this%20IP%20so%20we%20must%20open%20a%20support%20ticket%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-58001%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-58001%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Ken%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20say%2C%20everyone%20is%20prone%20to%20make%20a%20mistake%2C%20i'm%20sure%20that%20Microsoft%20has%20done%20the%20same%20in%20not%20posting%20that%26nbsp%3B13.100.4.192%20belongs%20to%20them.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooking%20at%20whois%2C%20you%20will%26nbsp%3Bsee%20that%20it%20does%20belong%20to%20them%20and%20seeing%20that%20it%20is%20STUN%20traffic%2C%20%26nbsp%3Bits%20most%20likely%20a%5Cv%20edge%20services%20or%20Microsoft%20Teams%20A%5CV%20channel...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-57675%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-57675%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Leonardo.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20taking%20your%20time%20to%20reply%2C%20but%20unfortunately%20your%20suggestion%20is%20not%20correct.%20The%20IP%20address%2013.100.4.192%20is%20not%20in%20the%20documented%20new%20ranges%20for%20Office%20365%20(13.107.64.0%2F18%20and%2052.112.0.0%2F14).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%2FKenneth%20ML%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-57636%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-57636%22%20slang%3D%22en-US%22%3EThe%20answer%20is%20here%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FSkype-Operations-Framework-Skype%2FUpdated-IP-ranges-and-ports-for-Skype-for-Business-Online%2Fba-p%2F47470%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FSkype-Operations-Framework-Skype%2FUpdated-IP-ranges-and-ports-for-Skype-for-Business-Online%2Fba-p%2F47470%3C%2FA%3E%3CBR%20%2F%3E%E2%80%A2%20New%20IP%20ranges%3A%20We%20already%20started%20to%20move%20the%20Skype%20for%20Business%20infrastructure%20to%20the%20following%20port%20ranges%3A%20%3CBR%20%2F%3Eo%2013.107.64.0%2F18%3CBR%20%2F%3Eo%2052.112.0.0%2F14%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-57480%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-57480%22%20slang%3D%22en-US%22%3E%3CP%3ESee%20that%20the%20src%20and%20dst%20ports%20are%20on%20the%20higher%20upper%20side%2C%20I'm%20think%20they%20may%20have%20CDN%20defined%20and%20that%20is%20the%20agent%20on%20the%20machine%3F%26nbsp%3B%20I%20know%20Hive%20agent%20uses%2040K%20to%2069K%20range.%20ALso%20the%20IP%20belongs%20to%20MSFT.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-853735%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-853735%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F17701%22%20target%3D%22_blank%22%3E%40Kenneth%20Meyer-Lassen%3C%2FA%3Edid%20you%20ever%20get%20to%20the%20bottom%20of%20the%2013.100.x.x%20phenomenon%20%3F%26nbsp%3B%20This%20is%20still%20not%20listed%20and%20I%20am%20seeing%20this%20in%20logs%20too%20and%20firewall%20dropping%20packets.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-853974%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-853974%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F329706%22%20target%3D%22_blank%22%3E%40umeshradia%3C%2FA%3E%26nbsp%3B%20I%20have%20unfortunately%20never%20gotten%20to%20the%20bottom%20of%20this%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20right%20now%20working%20with%20a%20financial%20customer%2C%20who%20has%20a%20more%20restrictive%20firewall%20policy%20than%20most%20companies.%20I%20will%20investigate%20if%20this%20is%20still%20occurring.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1313503%22%20slang%3D%22en-US%22%3ERe%3A%20Unknown%20Office%20365%20IP%20address%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1313503%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F17701%22%20target%3D%22_blank%22%3E%40Kenneth%20Meyer-Lassen%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Edo%20you%20guys%20fixed%20this%20by%20today%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20see%20this%20ip%20address%20too%26nbsp%3B%3C%2FP%3E%3CDIV%3E13.100.33.107%3C%2FDIV%3E%3C%2FLINGO-BODY%3E
Contributor

I saw at a customer site today, a STUN request going from the client to 13.100.4.192. By looking at the src and dest ports, I would say this is a video session trying to establish a connection to a meeting.

 

screenshot_2017-03-28_001.png

 

This IP address is not listed in any of the Office 365 IP ranges, so the traffic is blocked by the firewall. After some time the client tries to connect to a 52.112.0.0/14 host and the RTP flow is established towards this host.

 

This influences user experience as the connection takes longer time than necessary.

 

Does anyone know this IP address and which range should be allowed for this to connect??

 

/Kenneth ML

10 Replies

See that the src and dst ports are on the higher upper side, I'm think they may have CDN defined and that is the agent on the machine?  I know Hive agent uses 40K to 69K range. ALso the IP belongs to MSFT. 

The answer is here https://techcommunity.microsoft.com/t5/Skype-Operations-Framework-Skype/Updated-IP-ranges-and-ports-...
• New IP ranges: We already started to move the Skype for Business infrastructure to the following port ranges:
o 13.107.64.0/18
o 52.112.0.0/14

Hi Leonardo.

 

Thanks for taking your time to reply, but unfortunately your suggestion is not correct. The IP address 13.100.4.192 is not in the documented new ranges for Office 365 (13.107.64.0/18 and 52.112.0.0/14).

 

/Kenneth ML

Hi Ken,

 

I can say, everyone is prone to make a mistake, i'm sure that Microsoft has done the same in not posting that 13.100.4.192 belongs to them.

 

Looking at whois, you will see that it does belong to them and seeing that it is STUN traffic,  its most likely a\v edge services or Microsoft Teams A\V channel...

Yes I made a mistake, verify again the xml file was updated the 29th of march https://support.content.office.net/en-us/static/O365IPAddresses.xml ans still doesn't have this IP so we must open a support ticket

We noticed the same phenomenon. We had a lot of users reporting issues when having Skype for Business calls with external participants or when having a call with multiple participants. Both scenario's connect to SfB online. 

Internal point to point call did not show any issues.

 

This pointed us in the direction of the firewall in place between our network and the Microsoft (SfB) cloud environment.

 

After extensively going through the firewall logs and cross linking with the call quality dashboard now available on the Teams & Skype for Business admin portal we noticed a lot of drops by the firewall.

 

When investigating these drops we noticed a lot of inconsistencies with the documentation provided by Microsoft.

  • High ports range 50000-59999 should actually be 49152-65535
  • Connections towards 13.100.x.x ranges (UDP3478-3481) -> After WhoIs lookup the subnet is actually 13.96.0.0/13

This inconsistencies caused a lot of performance issues and users complaining about calls being dropped, content sharing issues, etc...

The 13.100 series are only the Host IPs. Not necessarily it needs to be route-able publicly.  It would by default try connecting direct and fail. We need to worry only about Relay IP which is 52.112 on most cases. 

 

a=candidate:1 1 tcp-pass 2120613887 13.100.10.217 61560 typ host
a=candidate:2 1 tcp-act 2121006591 13.100.10.217 62483 typ host
a=candidate:3 1 tcp-pass 174455807 52.112.0.193 59614 typ relay raddr 13.100.10.217 rport 61049
a=candidate:4 1 tcp-act 174848511 52.112.0.193 59614 typ relay raddr 13.100.10.217 rport 61049

@Kenneth Meyer-Lassendid you ever get to the bottom of the 13.100.x.x phenomenon ?  This is still not listed and I am seeing this in logs too and firewall dropping packets.

@umeshradia  I have unfortunately never gotten to the bottom of this issue.

 

I am right now working with a financial customer, who has a more restrictive firewall policy than most companies. I will investigate if this is still occurring.

@Kenneth Meyer-Lassen 

 

do you guys fixed this by today?

 

We see this ip address too 

13.100.33.107