Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ryanmaggs
Explorer

Microsoft Teams - QoS setup on firewall

I am trying to setup QoS rules on a cluster of two 3600 Appliances to prioritise Microsoft Teams traffic. It is setup on their Teams admin centre to use certain ranges of ports for real-time media traffic instead of any port in the range 1024-65535. I have already created a GPO to add the DSCP values to Teams audio, video and screen sharing traffic. I have used Wireshark to confirm these DSCP values are being added to the packets. I have created three separate services within SmartConsole as below and created rules on the QoS blade to target those services. However looking at the logs, all Teams traffic is hitting the first audio rule including video and screen sharing. Is this happening because Checkpoint only looks at the destination port, not the source port for QoS and that the destination port is the same for all three services?

Services created:

NameMatch By PortAdvanced > Source port
MSTeams_Audio3478-348150000-50019
MSTeams_Video3478-348150020-50039
MSTeams_ScreenSharing3478-348150040-50059
 All UDPAccept replies enabled on all

 

GPO QoS Microsoft Teams.png

Checkpoint QoS rules - Teams.png

 

Version running is R81.20 JHT 120 on Checkpoint firewalls

 

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Very likely this is what is happening.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events