Configuration · guide

Setting up CUBE as a Microsoft Teams Direct Routing SBC

Cisco Unified Border Element

Verified 2026-09-30 · 73 sources · tier 2 · 3 disputed

For Voice engineers configuring CUBE to pair with Microsoft Teams Direct Routing..

Direct Routing connects a certified session border controller to Microsoft Teams Phone over SIP/TLS and SRTP 65 66. This guide walks through configuring Cisco Unified Border Element (CUBE) and pairing it as an online PSTN gateway in Microsoft Teams 13 44.

Before you start

  • Direct Routing requires a Microsoft-certified SBC, PSTN trunks connected to it, users homed online, a public IP address, an SBC FQDN in a verified tenant domain (not *.onmicrosoft.com) with public DNS, and a publicly trusted TLS certificate 66.
  • Microsoft supports Teams Phone with Direct Routing only when certified SBCs are used 67.
  • Users must be licensed with Teams Phone and have a PSTN solution 68.
  • Direct Routing is not supported in Islands coexistence mode 69.

What changes by situation

Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.

Which SBC will terminate Direct Routing?
Will the trunk use media bypass?
Which Microsoft cloud is the tenant in?

Three questions. One permanent page you can send to your manager.

Step 1 Confirm the SBC and its software are certified

Cisco Unified Border Element

Do

Microsoft lists Cisco Unified Border Element as certified for Direct Routing, both non-media bypass and media bypass, on 1000 Series ISR, 4000 Series ISR, CSR 1000V, ASR 1000 and Catalyst 8000 Edge platforms 13. Cisco Unified Border Element is supported from IOS XE Amsterdam 17.2.1r (17.3.2 for Catalyst 8000 Edge), with 17.6.1a recommended (17.3.3 recommended for CSR 1000V) 23. Higher firmware versions are supported as long as the major.minor version matches a documented version 9. Note that CUBE rows are marked 911 Service Provider capable but not ELIN capable, and Cisco does not appear in the Local Media Optimization support table 17.

Verify

Suggested check: Run show version on the router and confirm the running release satisfies the platform requirements. Escalating an SBC issue to Microsoft requires presenting the SBC vendor's investigation report with a ticket reference 63.

Rollback

Suggested rollback: Downgrade or upgrade the platform firmware to an approved certified release before continuing.

Another certified SBC

Do

Confirm that your third-party SBC model and firmware version appear on Microsoft's certified list 67 9. Microsoft supports higher firmware versions as long as the major.minor version matches a documented version 9.

Verify

Suggested check: Check the administration page to confirm the running major.minor release matches the certified list.

Rollback

Suggested rollback: Apply a certified firmware release per your vendor's instructions before proceeding.

Step 2 Prepare the SBC FQDN, tenant domain, and DNS

Do

The SBC can only be connected if the domain portion of its FQDN matches a domain registered in the tenant other than *.onmicrosoft.com, and any subdomain used in the FQDN must itself be registered 34. Ensure that the tenant contains a user in the SBC's domain with an assigned E3 or E5 license, and that the domain's authentication type is Managed 33. Create a public DNS A record resolving the FQDN to the SBC public IP address 66. Direct Routing does not support mapping multiple IP addresses to the same FQDN on the SBC side 47.

Verify

Suggested check: Query public DNS for the SBC FQDN to ensure it returns a single public IP address, and confirm the domain is registered and verified.

Rollback

Suggested rollback: Remove the public DNS record for the SBC FQDN.

Step 3 Open the firewall for signaling and media to Microsoft

Microsoft 365, Office 365, or GCC

Do

Allow SIP/TLS from the SBC to the Microsoft SIP proxy on destination port 5061, and allow SIP/TLS from the Microsoft SIP proxy (source ports 1024-65535) to the port configured on the SBC 58. Direct Routing FQDNs resolve to 52.112.0.0/14 and 52.120.0.0/14, and Microsoft requires allowing signaling to and from all of these ranges rather than only the addresses DNS returns 57. For media between Microsoft media processors and the SBC, allow UDP/SRTP ports 3478-3481 and 49152-53247 in both directions 70. Microsoft recommends at least 2 media ports per concurrent call on the SBC 70. Sources disagree on the media processor ranges for commercial clouds: the Plan Direct Routing page specifies both 52.112.0.0/14 and 52.120.0.0/14, while the media bypass planning page lists only 52.112.0.0/14 41 40.

Verify

Suggested check: Validate outbound TCP connectivity on the signaling port to the primary SIP destination.

Rollback

Suggested rollback: Remove the firewall rules allowing signaling and media traffic to the cloud provider.

Office 365 GCC High

Do

Allow SIP/TLS signaling on port 5061 from the SBC to Microsoft, and from Microsoft source ports 1024-65535 to the configured SBC port 58. GCC High uses the single Direct Routing FQDN sip.pstnhub.gov.teams.microsoft.us and IP range 52.127.88.0/21, with no secondary or tertiary FQDNs 36. For media, allow UDP/SRTP ports 3478-3481 and 49152-53247 in both directions with at least 2 media ports per concurrent call on the SBC 70.

Verify

Suggested check: Validate outbound TCP connectivity on the signaling port to the designated government FQDN.

Rollback

Suggested rollback: Remove the firewall access rules for the government signaling and media destinations.

Office 365 DoD

Do

Allow SIP/TLS signaling on port 5061 from the SBC to Microsoft, and from Microsoft source ports 1024-65535 to the configured SBC port 58. DoD uses the single Direct Routing FQDN sip.pstnhub.dod.teams.microsoft.us and IP range 52.127.64.0/21, with no secondary or tertiary FQDNs 36. For media, allow UDP/SRTP ports 3478-3481 and 49152-53247 in both directions with at least 2 media ports per concurrent call on the SBC 70.

Verify

Suggested check: Validate outbound TCP connectivity on the signaling port to the designated defense FQDN.

Rollback

Suggested rollback: Remove the firewall access rules for the defense signaling and media destinations.

Step 4 Open client and relay media paths for bypass

Media bypass disabled

Do

Maintain direct media processor firewall rules only, as media bypass is disabled 70.

Verify

Suggested check: Confirm firewall rules do not allow client-to-SBC direct UDP media ports.

Rollback

Suggested rollback: No configuration change required.

Media bypass enabled

Do

Ensure Teams clients can reach the SBC's public IP address via UDP/SRTP from client ports 50000-50019 to the ports defined on the SBC, and back 3. Allow Teams Transport Relays to send from ports 50000-59999 to the SBC, and allow the SBC to reach relays on ports 50000-59999 and 3478-3481 7. Keep media processor ports open, as media processors stay in the path for voice applications (call park, auto attendants, call queues), web clients, escalations to group calls, calls to federated Teams users, and transfers to Skype for Business users 5. Do not use IPv6, because media bypass is not supported when IPv6 is used for SIP, media, or the Teams client 39.

Verify

Suggested check: Test UDP reachability between internal test client subnets and the SBC public IP address on the designated media ports.

Rollback

Suggested rollback: Remove the client port range and Transport Relay firewall rules.

Step 5 Install the public certificate and trust Microsoft's roots

Cisco Unified Border Element

Do

Generate an RSA key pair and a crypto pki trustpoint on CUBE with rsakeypair, fqdn, subject-name CN, subject-alt-name, enrollment terminal, and revocation-check settings 30. Generate the CSR on the SBC, ensure the certificate carries the SBC FQDN as CN or SAN, have it signed by a CA in the Microsoft Trusted Root Program, include the Server Authentication EKU, and note that RFC 2818 wildcards are supported 8. Microsoft SIP endpoints currently accept SBC certificates without the Client Authentication EKU 10. Import Microsoft's 7 root CAs into the trust store for both client and server certificates: DigiCert Global Root CA, DigiCert Global Root G2, DigiCert Global Root G3, DigiCert TLS ECC P384 Root G5, DigiCert TLS RSA 4096 Root G5, Microsoft ECC Root Certificate Authority 2017, and Microsoft RSA Root Certificate Authority 2017 56. Microsoft states that Direct Routing SIP endpoint certificates issued by a new CA were rolled out in production at the end of July 2026 43.

Verify

Suggested check: Run show crypto pki certificates on CUBE and verify the installed SBC certificate contains the SBC FQDN in the CN or SAN, and verify all root CAs appear in the trust store.

Rollback

Suggested rollback: Remove the trustpoint and delete the certificate and key pair with no crypto pki trustpoint <name>.

Another certified SBC

Do

Generate a CSR directly on the SBC, ensuring the SBC FQDN is present in the CN or SAN, that it is signed by a CA in the Microsoft Trusted Root Program, and that it includes the Server Authentication EKU 8. Import all 7 Microsoft root CAs into the SBC root store for both client and server certificate validation 56. Microsoft SIP endpoints currently accept certificates without the Client Authentication EKU 10.

Verify

Suggested check: Inspect the certificate management tab on the SBC to confirm the installed identity certificate matches the SBC FQDN and that all designated root CAs are trusted.

Rollback

Suggested rollback: Delete the installed certificate and private key using the vendor management interface.

Step 6 Enforce TLS 1.2 and SRTP toward Teams

Cisco Unified Border Element

Do

Under sip-ua, enforce TLS 1.2 using transport tcp tls v1.2 as the minimum version 28. Define the cipher suite under a voice class tls-cipher and bind the trustpoint and cipher in a voice class tls-profile 28. Microsoft forces TLS 1.2 and requires connecting with 1 of 4 ECDHE-RSA cipher suites: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384, or AES128-SHA256 61. Configure SRTP using voice class srtp-crypto 25. WarmTransfer's reading of the sources is that because Microsoft's example Teams-to-SBC offer uses RTP/SAVP with a=crypto AES_CM_128_HMAC_SHA1_80, the SBC leg toward Teams is SRTP with SDES keys 59. Apply SRTP globally under voice service voip sip, in a voice class tenant, or on the dial-peer with voice-class sip srtp-crypto, and enable secure calls on the dial-peer using srtp 25.

Verify

WarmTransfer's reading of the sources is that the administrator must confirm from the TLS connection detail that the negotiated suite is 1 of the 4 suites Microsoft accepts 14. Run show sip-ua connections tcp tls brief or show sip-ua connections tcp tls detail to verify active TLS connections 29. Run show sip-ua calls to display local and remote crypto keys to confirm SRTP negotiation 26.

Rollback

Suggested rollback: Remove the voice class tls-profile, voice class tls-cipher, and voice class srtp-crypto configurations from CUBE.

Another certified SBC

Do

Configure TLS 1.2 on the SBC SIP profile using 1 of Microsoft's 4 approved ECDHE-RSA ciphers: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384, or AES128-SHA256 61. Enable SRTP toward Microsoft Teams 66.

Verify

Suggested check: Check the SBC connection monitoring dashboard to verify the configured secure transport is negotiated and that active sessions show media encryption.

Rollback

Suggested rollback: Revert TLS and SRTP settings in the SBC vendor management interface.

Step 7 Build the Teams tenant and SIP header handling on CUBE

Cisco Unified Border Element

Do

Create a voice class tenant template for the Teams trunk; CUBE resolves settings in the order of dial-peer, then tenant, then global 27. In the tenant, configure session transport tcp tls, listen-port secure, and apply the voice class tls-profile 28. Direct Routing requires every OPTIONS and INVITE sent to Teams to carry the paired SBC FQDN in the Contact header, refusing an IP address with 403 Forbidden 12. Direct Routing matches the FQDN in Contact against the certificate's CN or SAN and uses that FQDN or parent domain to identify the tenant 11. Configure a voice class sip-profiles rule to modify or insert the SBC FQDN into the Contact header if needed, noting that outbound profiles apply via voice-class sip profiles on a dial-peer while inbound profiles require sip-profiles inbound 24. Ensure phone numbers in the Request-URI and From header carry a leading plus sign in +E.164 format, and add user=phone to the Request-URI as Microsoft recommends 50. Send early offer INVITEs with SDP, as Direct Routing does not support Delayed Offer INVITEs and does not support SIPS URIs 45.

Verify

Suggested check: Enable debug ccsip feature sip-profiles or run a SIP packet capture to verify that outgoing OPTIONS and INVITE messages carry the SBC FQDN in the Contact header with transport=tls and that phone numbers in the Request-URI carry a leading plus sign 24 12 50.

Rollback

Suggested rollback: Remove the voice class tenant and voice class sip-profiles from CUBE.

Another certified SBC

Do

Configure your SBC SIP profile to ensure the Contact header in all outbound OPTIONS and INVITE requests carries the paired SBC FQDN rather than an IP address 12. Direct Routing matches this FQDN against the certificate and uses it to find the tenant 11. Format Request-URI and From numbers with a leading plus sign (+E.164), append user=phone to the Request-URI, and ensure calls use early offer with SDP, avoiding Delayed Offer and SIPS URIs 50 45.

Verify

Suggested check: Capture a SIP trace on the SBC to verify that Contact headers present the SBC FQDN, Request-URIs include user=phone and a leading plus sign, and initial INVITEs include SDP.

Rollback

Suggested rollback: Revert SIP header manipulation profiles on the SBC.

Step 8 Configure the OPTIONS keepalive toward Teams

Cisco Unified Border Element

Do

Configure a voice class sip-options-keepalive profile with transport tcp tls 21. Direct Routing requires SIP OPTIONS from the SBC to be sent no more often than once every 60 seconds and no less often than once every 180 seconds per trunk per endpoint 48. The CUBE default up-interval is 60 seconds, which satisfies this requirement 21. When Direct Routing receives incoming OPTIONS from an SBC, it starts sending its own OPTIONS to the SBC FQDN given in the Contact header of those incoming OPTIONS 49. Attach the keepalive profile to the Teams dial-peer using voice-class sip options-keepalive profile <id> 21.

Verify

Run show voice class sip-options-keepalive <id>, show dial-peer voice summary, and show dial-peer voip keepalive status <tag> to verify keepalive state 20. When keepalive fails for every destination in a dial-peer, CUBE marks that dial-peer inactive (busyout) 20.

Rollback

Suggested rollback: Remove voice-class sip options-keepalive profile from the dial-peer and delete the voice class sip-options-keepalive profile.

Another certified SBC

Do

Enable SIP OPTIONS keepalive pings on the SBC toward Microsoft Direct Routing, setting the ping frequency to an interval between 60 and 180 seconds 48. Direct Routing will send its own OPTIONS to the FQDN received in your SBC's Contact header 49.

Verify

Suggested check: Review the SBC status page to confirm that outgoing OPTIONS receive successful responses.

Rollback

Suggested rollback: Disable SIP OPTIONS pings on the SBC trunk profile.

Step 9 Build dial-peers to Teams and to the carrier

Microsoft 365, Office 365, or GCC

Do

On CUBE, create a voice class server-group containing sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com, and sip3.pstnhub.microsoft.com in that priority order 71. Configure an outbound SIP dial-peer referencing the server group via session server-group, applying voice-class sip tenant, the options-keepalive profile, and bind interfaces 16. Configure inbound dial-peer matching with incoming uri 16. Configure codecs supported by Direct Routing: SILK, G.711, G.722, G.729, or AMR-WB (AMR-WB is supported only without media bypass) 72. Configure CUBE to stop retrying on a 603 response, otherwise a user who declines a call sees several missed calls 1. Configure carrier-facing dial-peers for PSTN connectivity 66.

Verify

Run show dial-peer voice summary to confirm dial-peers are active and operational 20.

Rollback

Suggested rollback: Remove or shut down the outbound and inbound dial-peers configured for Direct Routing.

Office 365 GCC High

Do

On CUBE, configure an outbound SIP dial-peer referencing a voice class server-group containing the single FQDN sip.pstnhub.gov.teams.microsoft.us 36 16. Apply the voice-class sip tenant, options-keepalive profile, and bind interfaces 16. Configure inbound matching using incoming uri 16. Configure codecs supported by Direct Routing (SILK, G.711, G.722, G.729, or AMR-WB without bypass) 72. Configure CUBE to stop retrying on a 603 response 1. Configure carrier-facing dial-peers 66.

Verify

Run show dial-peer voice summary to confirm the dial-peers are active and operational 20.

Rollback

Suggested rollback: Remove or shut down the GCC High dial-peers on CUBE.

Office 365 DoD

Do

On CUBE, configure an outbound SIP dial-peer referencing a voice class server-group containing the single FQDN sip.pstnhub.dod.teams.microsoft.us 36 16. Apply voice-class sip tenant, the options-keepalive profile, and bind interfaces 16. Configure inbound matching using incoming uri 16. Configure codecs supported by Direct Routing (SILK, G.711, G.722, G.729, or AMR-WB without bypass) 72. Configure CUBE to stop retrying on a 603 response 1. Configure carrier-facing dial-peers 66.

Verify

Run show dial-peer voice summary to confirm the dial-peers are active and operational 20.

Rollback

Suggested rollback: Remove or shut down the DoD dial-peers on CUBE.

Step 10 Pair CUBE as an online PSTN gateway in Teams

Media bypass disabled

Do

Pair the SBC either in the Teams admin center under Voice > Direct Routing > SBCs > Add, or by running PowerShell New-CsOnlinePSTNGateway -Fqdn <SBC-FQDN> -SipSignalingPort <port> -MaxConcurrentSessions <number> -Enabled $true 44. For GCC High and DoD clouds, PowerShell must be used because the option is not available in the Teams admin center 37. Leave SendSIPOptions set to True (the default), as turning it off excludes the SBC from monitoring and alerting 55. Keep MediaBypass disabled ($false) 4.

Verify

Run Get-CsOnlinePSTNGateway and confirm the SBC is listed with Enabled True 64. Validate that the SBC receives 200 OK to its outgoing OPTIONS and answers Direct Routing's incoming OPTIONS with 200 OK 64. In the Teams admin center health dashboard, confirm TLS connectivity status is active and SIP options status is Active 32 31.

Rollback

Set Enabled to false using Set-CsOnlinePSTNGateway -Identity <SBC-FQDN> -Enabled $false to take the SBC out of service, or remove it with Remove-CsOnlinePSTNGateway 55.

Media bypass enabled

Do

Pair the SBC in Teams using New-CsOnlinePSTNGateway or the Teams admin center, then enable bypass using Set-CsOnlinePSTNGateway -Identity <SBC-FQDN> -MediaBypass $true 44 4. For GCC High and DoD clouds, use PowerShell because pairing is not available in the Teams admin center 37. On CUBE, configure voice class stun-usage <tag> with stun usage ice lite, and apply it to the Teams dial-peer with voice class stun-usage 18 16. Ensure unsupported ICE-Lite features are not enabled: Cisco lists IPv6, ANAT, codec transparent, SDP passthrough, media flow-around, MTP, and TCL/VXML scripts as unsupported with ICE-Lite 18. Ensure the SBC handles REFER, which is mandatory for media bypass certification, as transfer without SBC REFER handling is not supported in media bypass mode 51. The SBC must also support ICE restarts when calls are transferred to endpoints that do not support media bypass 38. To pilot bypass, Microsoft describes configuring a second trunk FQDN on the same SBC with media bypass enabled, a different TLS signaling port, the same media ports, a certificate covering both names, and a separate voice routing policy 6.

Verify

Confirm pairing via Get-CsOnlinePSTNGateway with Enabled True and successful 200 OK OPTIONS responses in both directions 64. Verify ICE-Lite on CUBE using show voip ice summary, show voip ice instance call-id <id>, show voip ice global-stats, or show voip rtp connections 19.

Rollback

Run Set-CsOnlinePSTNGateway -Identity <SBC-FQDN> -MediaBypass $false and remove the stun-usage class from the Teams dial-peer 4 16.

Step 11 Configure voice routing in Teams

Do

Configure call routing elements in PowerShell using Set-CsOnlinePstnUsage to add a usage, New-CsOnlineVoiceRoute with -NumberPattern, -OnlinePstnGatewayList and -OnlinePstnUsages, New-CsOnlineVoiceRoutingPolicy, and Grant-CsOnlineVoiceRoutingPolicy 53. Do not edit the global (org-wide default) online voice routing policy to add the Direct Routing usage, as it applies to all voice-enabled users and can route Calling Plan and Operator Connect users' calls to the Direct Routing trunk 35. Direct Routing evaluates PSTN usages in order and the first match wins, while SBCs within a single voice route are tried in random order 54.

Verify

Verify policy assignment by running Get-CsOnlineUser <upn> | select OnlineVoiceRoutingPolicy 53.

Rollback

Suggested rollback: Run Grant-CsOnlineVoiceRoutingPolicy -Identity <upn> -PolicyName $null to remove the custom routing policy from test users, then delete the voice route and PSTN usage.

Step 12 Enable pilot users with Direct Routing numbers

Do

Assign each pilot user a phone number using Set-CsPhoneNumberAssignment -Identity <user> -PhoneNumber <number> -PhoneNumberType DirectRouting (or configure it on the user's page in the Teams admin center), which also enables Enterprise Voice 2. Microsoft recommends using full E.164 format 2. Ensure the users are in Teams Only mode (UpgradeToTeams instance of TeamsUpgradePolicy) so incoming calls land in the Teams client 60.

Verify

Suggested check: Check the user details in the administration portal under user management to confirm the assigned telephone number is listed with type Direct Routing.

Rollback

Suggested rollback: Remove the phone number assignment in the administration portal.

Step 13 Test calls end to end

Do

Execute Microsoft's post-configuration validation checklist: verify a healthy SBC connection, place inbound and outbound PSTN calls, test emergency calling if configured, verify failover between SIP connection points, confirm voice routing policy assignment, and assess call quality 62. Test call transfers, noting that if the SBC advertises REFER in its Allow header, Direct Routing sends REFER for transfers 51. Reject an incoming test call to confirm the SBC stops retrying after receiving a 603 response 1. Direct Routing requires specific emergency call routing policies, unlike carrier-managed PSTN models where the carrier handles emergency routing 73. Note that Direct Routing does not support media re-targeting: if the SBC signals a new media IP address mid-call, Direct Routing never sends media to the new address 46.

Verify

On CUBE, run show sip-ua calls to inspect the local and remote crypto keys and confirm SRTP media encryption on the call 26. When evaluating the Direct Routing health dashboard, note that the network effectiveness ratio counts answered, busy, ring-no-answer, and terminal-reject calls as delivered, and with fewer than 100 calls analysed, a low ratio can still be normal 42.

Rollback

Suggested rollback: Investigate failed calls by inspecting SIP traces on CUBE and review dial-peer matching and firewall logs.

Step 14 Hand over monitoring and support

Do

Monitor the Direct Routing health dashboard in the Teams admin center (Voice > Direct Routing) 32. The dashboard displays per-SBC TLS connectivity status and warns when an SBC certificate will expire within 30 days 32. Track the dashboard's SIP options status: it displays Active when OPTIONS flow regularly, 'Warning, no SIP options' when a configured SBC's OPTIONS were never seen, and 'Warning, SIP Messages aren't configured' when OPTIONS monitoring is off 31. Document the operational support process: to escalate an SBC-related Direct Routing issue to Microsoft, first open a ticket with the SBC vendor and obtain their investigation report and ticket reference, as Microsoft requires the vendor's report before escalating 63.

Verify

Check the Teams admin center Direct Routing dashboard to confirm the SBC status is Active with no TLS or SIP options warnings 31.

Rollback

Suggested rollback: No ongoing rollback needed for monitoring setup.

Applicability

Applies to: Microsoft Teams Phone and Cisco Unified Border Element. Deployments: on-premises, multi-tenant, dod, gcc, and gcc-high. Sources checked 2026-09-30. Microsoft lists CUBE as supported starting from IOS XE Amsterdam 17.2.1r (17.3.2 for Catalyst 8000 Edge), with 17.6.1a recommended (17.3.3 recommended for CSR 1000V) 23. GCC High uses sip.pstnhub.gov.teams.microsoft.us and DoD uses sip.pstnhub.dod.teams.microsoft.us, where pairing must be completed with PowerShell rather than the Teams admin center 36 37.

What remains uncertain

Sources disagree on the media processor IP ranges for commercial Microsoft 365 and Office 365 environments: the Plan Direct Routing documentation specifies both 52.112.0.0/14 and 52.120.0.0/14, whereas the media bypass planning documentation lists only 52.112.0.0/14 41 40. In addition, sources disagree regarding SIP Replaces handling: Microsoft's SIP protocol documentation states that Direct Routing rejects SIP requests carrying a Replaces header, while also stating elsewhere on the same page that the SBC must support INVITE with Replaces 52. Exact PowerShell syntax for unassigning Direct Routing phone numbers was not covered by the sources below.

See also

Configures

  • Cisco unified border elementstub — Guide configures CUBE (IOS XE) as the customer SBC: certificate and trustpoint; TLS 1.2; SRTP; tenant; SIP profiles; OPTIONS keepalive; dial-peers; ICE-Lite for media bypass.

Integrates with

  • Microsoft teams phone — Guide covers the Teams side of Direct Routing: online PSTN gateway; PSTN usages; voice routes; voice routing policies; user number assignment and health dashboard.

Referenced by

Sources

  1. 1
    The SBC must be configured to stop retrying on a 603 response; otherwise a user who declines a call sees several missed calls.
    Teams Phone System Direct Routing: SIP protocol · Handling retries (603 response) · Checked 2026-09-30
  2. 2
    A Direct Routing number is assigned with Set-CsPhoneNumberAssignment -PhoneNumber <number> -PhoneNumberType DirectRouting (or in the Teams admin center user page), which also enables Enterprise Voice; Microsoft recommends full E.164 format.
    Enable users for Direct Routing · Configure the phone number and enable enterprise voice · Checked 2026-09-30
  3. 3
    For direct bypass media, Teams clients must reach the SBC's public IP: UDP/SRTP from client ports 50000-50019 to ports defined on the SBC, and back.
    Plan for media bypass with Direct Routing · Requirements for direct media traffic (between the Teams client and the SBC) · Checked 2026-09-30
  4. 4
    Media bypass keeps media between the SBC and the Teams client using ICE on the client and ICE Lite on the SBC, is set per SBC with Set-CsOnlinePSTNGateway -MediaBypass, and signaling still always flows through the Microsoft cloud.
    Plan for media bypass with Direct Routing · About media bypass with Direct Routing; Call flow if the user has direct access to the public IP address of the SBC · Checked 2026-09-30
  5. 5
    Even on a media bypass trunk, Microsoft media processors stay in the path for voice applications (call park, auto attendants, call queues), web clients, escalations to group calls, calls to federated Teams users and transfers to Skype for Business users.
    Plan for media bypass with Direct Routing · Use of Media Processors and Transport Relays; Use of Teams Media Processors if trunk is configured for media bypass; Requirements for using media processors · Checked 2026-09-30
  6. 6
    To pilot media bypass, Microsoft describes a second trunk FQDN on the same SBC with media bypass enabled, a different TLS signaling port, the same media ports, a certificate covering both names, and a separate voice routing policy for the test users.
    Plan for media bypass with Direct Routing · Configure separate trunks for media bypass and non-media bypass · Checked 2026-09-30
  7. 7
    With media bypass, Teams Transport Relays send from ports 50000-59999 to the SBC, and the SBC must be able to reach relays on 50000-59999 and 3478-3481 because two relay versions are in use.
    Plan for media bypass with Direct Routing · Requirements for using Transport Relays, port table and note · Checked 2026-09-30
  8. 8
    Microsoft recommends generating the SBC certificate from a CSR on the SBC; the certificate should carry the SBC FQDN as CN or SAN, be signed by a CA in the Microsoft Trusted Root Program and include the Server Authentication EKU, and RFC 2818 wildcards are supported.
    Plan Direct Routing · Public trusted certificate for the SBC · Checked 2026-09-30
  9. 9
    Microsoft certifies specific SBC firmware versions and supports higher firmware versions as long as the major.minor version is the same as a documented version.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Introductory note on certification before the Certified SBC vendors table · Checked 2026-09-30
  10. 10
    Microsoft SIP endpoints currently accept SBC certificates without the Client Authentication EKU and say they will announce any change in advance.
    What's New Direct Routing · Clarification on Client Authentication Extended Key Usage (EKU) · Checked 2026-09-30
  11. 11
    Direct Routing matches the FQDN in the Contact header against the certificate's CN or SAN (wildcards allowed) and then uses that FQDN, or its parent domain, to find the tenant; a mismatch fails the call.
    Teams Phone System Direct Routing: SIP protocol · Processing the incoming request: finding the tenant and user, steps 1-3; Use of FQDN name in Contact or Record-Route · Checked 2026-09-30
  12. 12
    Every OPTIONS and INVITE the SBC sends to Direct Routing must carry the paired SBC FQDN in the Contact header; a Contact with an IP address is refused with 403 Forbidden.
    Teams Phone System Direct Routing: SIP protocol · Detailed requirements for Contact header and Request-URI > Contact header · Checked 2026-09-30
  13. 13
    Microsoft lists Cisco Unified Border Element as certified for Direct Routing, both non-media bypass and media bypass, on 1000 Series ISR, 4000 Series ISR, CSR 1000V, ASR 1000 and Catalyst 8000 Edge platforms.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, Cisco rows · Checked 2026-09-30
  14. 14
    Because Microsoft accepts only four ECDHE-RSA suites and Cisco's CUBE example tls-cipher names are AES128_GCM_SHA256 and AES256_GCM_SHA384, the administrator must confirm from the TLS connection detail that the negotiated suite is one Microsoft accepts.inferred
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · TLS cipher configuration example, read against ms-learn-dr-connect-sbc Considerations TLS bullet · Checked 2026-09-30
  15. 15
    Because Cisco's command reference describes localhost dns as covering From, Call-ID and Remote-Party-ID but Microsoft requires the SBC FQDN specifically in Contact, an administrator should confirm the Contact header in a CUBE SIP trace and correct it with a SIP profile if it still carries an IP.inferred
    Cisco IOS Voice Command Reference - K through R - L · localhost command entry, read against ms-learn-dr-protocols-sip Contact header section · Checked 2026-09-30
  16. 16
    IOS XE SIP dial-peers can reference a voice class server-group (session server-group), a tenant (voice-class sip tenant), an OPTIONS keepalive profile, a voice class stun-usage, an e164-pattern-map destination, incoming URI matching and separate bind control and bind media interfaces.
    SIP Dial Peer Configurations - IOS-XE VoIP · SIP Dial Peer Configurations: session server-group, voice-class sip tenant, options-keepalive profile, voice class stun-usage, destination e164-pattern-map, incoming uri, bind · Checked 2026-09-30
  17. 17
    In Microsoft's certified SBC list the CUBE rows are marked 911 Service Provider capable but not ELIN capable, and Cisco does not appear in the Local Media Optimization support table.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table Cisco rows (ELIN capable column); Support for Local Media Optimization table · Checked 2026-09-30
  18. 18
    CUBE ICE-Lite is configured with voice class stun-usage <tag> and 'stun usage ice lite', and Cisco lists IPv6, ANAT, codec transparent, SDP passthrough, media flow-around, MTP and TCL/VXML scripts as unsupported with it.
  19. 19
    Cisco documents show voip ice summary, show voip ice instance call-id <id>, show voip ice global-stats and show voip rtp connections to verify ICE-Lite on CUBE.
  20. 20
    When OPTIONS keepalive fails for every destination of a dial-peer, CUBE marks that dial-peer inactive (busyout); status is shown by show voice class sip-options-keepalive <id>, show dial-peer voice summary and show dial-peer voip keepalive status <tag>.
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Trunk Monitoring · Feature description; verification section · Checked 2026-09-30
  21. 21
    A CUBE voice class sip-options-keepalive profile sets up-interval (default 60 s), down-interval (default 30 s), retry (default 5), transport (including tcp tls) and sip-profiles, and is attached to a dial-peer with voice-class sip options-keepalive profile <id>.
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Trunk Monitoring · Configuring the keepalive profile; applying to dial peers · Checked 2026-09-30
  22. 22
    Cisco's localhost dns:<host.domain> command substitutes a DNS name for the physical IP in the From, Call-ID and Remote-Party-ID headers of outgoing messages, and voice-class sip localhost overrides it per dial-peer.
    Cisco IOS Voice Command Reference - K through R - L · localhost command entry · Checked 2026-09-30
  23. 23
    Microsoft lists CUBE as supported from IOS XE Amsterdam 17.2.1r (17.3.2 for Catalyst 8000 Edge) with 17.6.1a recommended (17.3.3 recommended for CSR 1000V).
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Certified SBC vendors table, Cisco rows, Software version column · Checked 2026-09-30
  24. 24
    CUBE SIP profiles (voice class sip-profiles) add, modify or remove SIP and SDP headers with request/response rules; they apply outbound via voice-class sip profiles on a dial-peer, while inbound profiles need 'sip-profiles inbound' enabled first; debug ccsip feature sip-profiles traces them.
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Profiles · SIP profile configuration; inbound SIP profiles; verification and troubleshooting · Checked 2026-09-30
  25. 25
    CUBE's voice class srtp-crypto lists preferred SRTP suites (AEAD_AES_256_GCM, AEAD_AES_128_GCM, AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32) and can be applied globally under voice service voip sip, in a voice class tenant, or per dial-peer with voice-class sip srtp-crypto, with 'srtp' enabling secure calls on the dial-peer.
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking · Voice class srtp-crypto configuration; application at global, tenant and dial-peer levels · Checked 2026-09-30
  26. 26
    Cisco documents 'show sip-ua calls' as displaying the local and remote crypto keys of a CUBE call, which confirms SRTP was negotiated.
  27. 27
    A CUBE voice class tenant acts as a per-trunk configuration template applied with voice-class sip tenant <tag>, and settings resolve in the order dial-peer, then tenant, then global.
  28. 28
    On CUBE, TLS 1.2 can be enforced globally with 'transport tcp tls v1.2' (minimum form) under sip-ua, ciphers are listed in voice class tls-cipher and bound with a trustpoint in voice class tls-profile, and a voice class tenant can apply the tls-profile with 'session transport tcp tls' and 'listen-port secure'.
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · TLS cipher, TLS profile and SIP-UA/tenant configuration sections · Checked 2026-09-30
  29. 29
    Cisco documents 'show sip-ua connections tcp tls brief' and 'show sip-ua connections tcp tls detail' to verify CUBE TLS connections.
  30. 30
    Cisco's CUBE SIP TLS chapter builds the CUBE identity by generating an RSA key pair and a crypto pki trustpoint with rsakeypair, fqdn, subject-name CN, subject-alt-name, enrollment terminal and revocation-check settings.
    Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support · Certificate creation / trustpoint configuration section · Checked 2026-09-30
  31. 31
    The dashboard's SIP options status is Active when OPTIONS flow regularly, 'Warning, no SIP options' when a configured SBC's OPTIONS were never seen, and 'Warning, SIP Messages aren't configured' when OPTIONS monitoring is off.
    Health dashboard for Direct Routing · The SBCs tab > SIP options status · Checked 2026-09-30
  32. 32
    The Direct Routing health dashboard in the Teams admin center (Voice > Direct Routing) shows a per-SBC TLS connectivity status and warns when the SBC certificate expires within 30 days.
    Health dashboard for Direct Routing · View the health dashboard; The SBCs tab > TLS connectivity status · Checked 2026-09-30
  33. 33
    The tenant must have a user in the SBC's domain with an assigned E3 or E5 license, and that domain's authentication type must be Managed; otherwise pairing fails with a 'domain was not configured for this tenant' error.
    Connect your Session Border Controller (SBC) to Direct Routing · Connect the SBC to the tenant > Considerations, second and third bullets · Checked 2026-09-30
  34. 34
    The SBC can only be connected if the domain portion of its FQDN matches a domain registered in the tenant other than *.onmicrosoft.com, and a subdomain used in the FQDN must itself be registered.
    Connect your Session Border Controller (SBC) to Direct Routing · Use the Microsoft Teams admin center, item 3; Considerations list · Checked 2026-09-30
  35. 35
    Configuring the global (org-wide default) online voice routing policy applies it to all voice-enabled users and can send Calling Plan and Operator Connect users' calls to the Direct Routing trunk; Microsoft advises a custom policy assigned to individual users instead.
    Configure call routing for Direct Routing · Voice routing policy considerations, Caution item 1 · Checked 2026-09-30
  36. 36
    GCC High uses the single Direct Routing FQDN sip.pstnhub.gov.teams.microsoft.us (52.127.88.0/21) and DoD uses sip.pstnhub.dod.teams.microsoft.us (52.127.64.0/21), with no secondary or tertiary FQDNs.
    Plan Direct Routing · SIP signaling: GCC High; SIP signaling: DoD; Media processor IP ranges · Checked 2026-09-30
  37. 37
    For GCC High and DoD clouds the SBC must be connected with PowerShell because the option is not available in the Teams admin center.
    Connect your Session Border Controller (SBC) to Direct Routing · Note after the introduction · Checked 2026-09-30
  38. 38
    The SBC must support ICE restarts because Direct Routing restarts ICE with new candidates when a bypassed call is transferred to a Skype for Business, Teams web or Teams VDI client.
    Teams Phone System Direct Routing: SIP protocol · ICE Restart: Media bypass call transferred to an endpoint that doesn't support media bypass · Checked 2026-09-30
  39. 39
    Media bypass is not supported when IPv6 is used for SIP, media or the Teams client; IPv6 Direct Routing is supported only without media bypass and with IPv6 for both signaling and media.
    What's New Direct Routing · IPv6 with non media bypass is now supported for Teams Phone · Checked 2026-09-30
  40. 40
    The media bypass planning page lists only 52.112.0.0/14 as the media processor and transport relay range for Microsoft 365, Office 365 and GCC.disputed
    Plan for media bypass with Direct Routing · Requirements for using Transport Relays; Requirements for using media processors · Checked 2026-09-30
  41. 41
    The Plan Direct Routing page tells administrators to allow media traffic for both 52.112.0.0/14 and 52.120.0.0/14 for Microsoft 365 and Office 365.disputed
    Plan Direct Routing · Media processor IP ranges > Microsoft 365 / Office 365 · Checked 2026-09-30
  42. 42
    The dashboard's network effectiveness ratio counts answered, busy, ring-no-answer and terminal-reject calls as delivered, and with fewer than 100 calls analysed a low ratio can still be normal.
    Health dashboard for Direct Routing · The SBCs tab > Network effectiveness · Checked 2026-09-30
  43. 43
    Microsoft states that Direct Routing SIP endpoint certificates issued by a new CA were rolled out in production at the end of July 2026 and that the sip.g1.pstnhub.microsoft.com testing endpoint is discontinued.
    What's New Direct Routing · Testing endpoint for upcoming certificate changes (February 16, 2026), Warning box · Checked 2026-09-30
  44. 44
    An SBC is paired either in the Teams admin center under Voice > Direct Routing > SBCs > Add, or with New-CsOnlinePSTNGateway using -Fqdn, -SipSignalingPort, -MaxConcurrentSessions and -Enabled $true.
    Connect your Session Border Controller (SBC) to Direct Routing · Use the Microsoft Teams admin center; Use PowerShell > Connect the SBC to the tenant · Checked 2026-09-30
  45. 45
    Direct Routing does not support Delayed Offer INVITEs (INVITE without SDP) and does not support SIPS URIs.
    Teams Phone System Direct Routing: SIP protocol · Non-media bypass flow note; note under Processing the incoming request · Checked 2026-09-30
  46. 46
    Direct Routing does not support media re-targeting: if the SBC signals a new media IP mid-call, Direct Routing never sends media to the new address.
  47. 47
    Mapping multiple IP addresses to the same FQDN on the SBC side is not supported for Direct Routing.
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations list, bullet on multiple IPs · Checked 2026-09-30
  48. 48
    SIP OPTIONS from the SBC must be sent no more often than once every 60 seconds and no less often than once every 180 seconds per trunk per endpoint.
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations list, SIP OPTIONS pings bullet · Checked 2026-09-30
  49. 49
    When Direct Routing sees incoming OPTIONS from an SBC it starts sending its own OPTIONS to the SBC FQDN given in the Contact header of those incoming OPTIONS.
    Connect your Session Border Controller (SBC) to Direct Routing · Verify the SBC connection > Validate SIP options · Checked 2026-09-30
  50. 50
    For incoming calls Direct Routing requires the phone numbers in the Request-URI and the From header to carry a leading plus sign, and Microsoft recommends always adding user=phone to the Request-URI.
    Teams Phone System Direct Routing: SIP protocol · Request-URI; From Header; Use of Request-URI parameter user=phone · Checked 2026-09-30
  51. 51
    If the SBC advertises REFER in its Allow header, Direct Routing sends REFER to the SBC for transfers; this method is mandatory for media bypass certification, and transfer without SBC REFER handling is not supported in media bypass mode.
    Teams Phone System Direct Routing: SIP protocol · Call transfer; SIP proxy send the Refer to the SBC and acts as a Transferor · Checked 2026-09-30
  52. 52
    Microsoft's SIP protocol page both says Direct Routing rejects SIP requests that carry a Replaces header and says the SBC must support INVITE with Replaces.disputed
    Teams Phone System Direct Routing: SIP protocol · Note under Processing the incoming request (Replaces headers); Replaces option section · Checked 2026-09-30
  53. 53
    The PowerShell sequence for routing is Set-CsOnlinePstnUsage to add a usage, New-CsOnlineVoiceRoute with -NumberPattern, -OnlinePstnGatewayList and -OnlinePstnUsages, New-CsOnlineVoiceRoutingPolicy, and Grant-CsOnlineVoiceRoutingPolicy, verified with Get-CsOnlineUser selecting OnlineVoiceRoutingPolicy.
    Configure call routing for Direct Routing · Example 1: Configuration steps > Using PowerShell, steps 1-4 · Checked 2026-09-30
  54. 54
    Direct Routing call routing uses voice routing policies that contain ordered PSTN usages, which contain voice routes pairing a number pattern with online PSTN gateways; usages are evaluated in order and the first match wins, and SBCs within one route are tried in random order.
    Configure call routing for Direct Routing · Call routing overview; Example 1 note on random order; Example 2 note on PSTN usage order · Checked 2026-09-30
  55. 55
    Online PSTN gateway defaults are SendSIPOptions True (turning it off excludes the SBC from monitoring and alerting), FailoverResponseCodes 408, 503 and 504, and FailoverTimeSeconds 10; Enabled can be set false to take the SBC out of service for maintenance.
    Connect your Session Border Controller (SBC) to Direct Routing · SBC settings table rows Enabled, Send SIP options, Failover response codes, Failover times · Checked 2026-09-30
  56. 56
    SBCs must trust seven root CAs for the Microsoft Teams SIP interface: DigiCert Global Root CA, DigiCert Global Root G2, DigiCert Global Root G3, DigiCert TLS ECC P384 Root G5, DigiCert TLS RSA 4096 Root G5, Microsoft ECC Root Certificate Authority 2017 and Microsoft RSA Root Certificate Authority 2017, for both client and server certificates.
    What's New Direct Routing · Update on upcoming certificate changes (December 12, 2025) > Changes and call to action; Summary · Checked 2026-09-30
  57. 57
    The commercial and GCC Direct Routing FQDNs resolve to 52.112.0.0/14 and 52.120.0.0/14, and Microsoft says to allow signaling to and from all these ranges rather than only the addresses DNS returns.
    Plan Direct Routing · SIP signaling: FQDNs, IP ranges and Important note · Checked 2026-09-30
  58. 58
    SIP/TLS from the SBC goes to the Microsoft SIP proxy on port 5061, and SIP/TLS from the Microsoft SIP proxy (source ports 1024-65535) goes to the port configured on the SBC.
    Plan Direct Routing · SIP signaling ports table · Checked 2026-09-30
  59. 59
    Microsoft's example Teams-to-SBC offer uses RTP/SAVP with a=crypto AES_CM_128_HMAC_SHA1_80, so the SBC leg toward Teams is SRTP with SDES keys.inferred
    What's New Direct Routing · AMR-WB is enabled for Direct Routing trunks on non bypass calls, SDP before/after example · Checked 2026-09-30
  60. 60
    Direct Routing requires users to be in Teams Only mode (the UpgradeToTeams instance of TeamsUpgradePolicy) so that incoming calls land in the Teams client.
    Enable users for Direct Routing · Assign Teams Only mode to users to ensure calls land in Microsoft Teams · Checked 2026-09-30
  61. 61
    Microsoft forces TLS 1.2 on the Direct Routing SIP interface and requires the SBC to connect with one of four ECDHE-RSA cipher suites: AES256-GCM-SHA384, AES128-GCM-SHA256, AES256-SHA384 or AES128-SHA256.
    Connect your Session Border Controller (SBC) to Direct Routing · Considerations list, TLS1.2 bullet · Checked 2026-09-30
  62. 62
    Microsoft's post-configuration checklist is to verify a healthy SBC connection, inbound and outbound PSTN calling, emergency calling if configured, failover between SIP connection points, voice routing policy assignment and call quality.
    Plan Direct Routing · Verify your deployment · Checked 2026-09-30
  63. 63
    To escalate an SBC-related Direct Routing issue to Microsoft, the customer must first contact the SBC vendor and present the vendor's investigation report with its ticket reference.
    Session Border Controllers certified for Direct Routing - Microsoft Teams · Note under 'Establish a joint support process with the SBC vendors' · Checked 2026-09-30
  64. 64
    Microsoft's pairing check is that Get-CsOnlinePSTNGateway lists the SBC with Enabled True and that the SBC both receives 200 OK to its outgoing OPTIONS and answers Direct Routing's OPTIONS with 200 OK.
    Connect your Session Border Controller (SBC) to Direct Routing · Verify the SBC connection > Check whether the SBC is on the list of paired SBCs; Validate SIP options · Checked 2026-09-30
  65. 65
    Direct Routing lets an organization use any PSTN operator by connecting it through a certified SBC that is procured, installed and managed by the customer, an integrator or a Direct-Routing-as-a-Service provider.
    PSTN connectivity options · PSTN connectivity options, bullet 'Direct Routing' · Checked 2026-09-24
  66. 66
    Direct Routing requires a Microsoft-certified SBC, PSTN trunks to it, users homed online, a public IP, an SBC FQDN in a verified tenant domain (not *.onmicrosoft.com) with public DNS, and a publicly trusted TLS certificate.
    Plan Direct Routing · Plan Direct Routing, section 'Infrastructure requirements' table and section 'SBC domain names' · Checked 2026-09-24
  67. 67
    Microsoft supports Teams Phone with Direct Routing only when certified SBCs are used, expects the SBC vendor to investigate first and escalate, and may decline support requests involving non-certified SBCs.
    Plan Direct Routing · Plan Direct Routing, sections 'Supported Session Border Controllers (SBCs)' and 'Support boundaries' · Checked 2026-09-24
  68. 68
    To use PSTN telephony with Teams Phone, a user account must be licensed with the Teams Phone application and also be equipped with a PSTN solution from a PSTN service provider.
    PSTN connectivity options · PSTN connectivity options, section 'What is the Public Switched Telephone Network (PSTN)?' · Checked 2026-09-24
  69. 69
    Direct Routing is not supported in Islands coexistence mode.
    Plan Direct Routing · Plan Direct Routing, section 'Licensing requirements', Note · Checked 2026-09-24
  70. 70
    Direct Routing media between Microsoft media processors and the SBC uses UDP/SRTP ports 3478-3481 and 49152-53247 in both directions, and Microsoft recommends at least two media ports per concurrent call on the SBC.
    Plan Direct Routing · Plan Direct Routing, section 'Media ports' table and Tip · Checked 2026-09-24
  71. 71
    For Microsoft 365, Office 365 and GCC, the SBC connects to sip.pstnhub.microsoft.com, sip2.pstnhub.microsoft.com and sip3.pstnhub.microsoft.com in priority order over SIP/TLS to port 5061; GCC High uses sip.pstnhub.gov.teams.microsoft.us and DoD uses sip.pstnhub.dod.teams.microsoft.us.
    Plan Direct Routing · Plan Direct Routing, sections 'SIP signaling: FQDNs', 'SIP signaling: GCC High', 'SIP signaling: DoD', 'SIP signaling ports' · Checked 2026-09-24
  72. 72
    Direct Routing supports SILK, G.711, G.722, G.729 and AMR-WB between Teams and the SBC, with AMR-WB supported only without media bypass.
    Plan Direct Routing · Plan Direct Routing, section 'Supported codecs' · Checked 2026-09-24
  73. 73
    Direct Routing requires specific emergency call routing policies, whereas with the other PSTN options the carrier handles much of the emergency call routing configuration.
    Plan and manage emergency calling · Plan and manage emergency calling, section 'Emergency call routing' · Checked 2026-09-24

Documents

tier 2 current vendor documentation

Cisco IOS Voice Command Reference - K through R - L

Cisco · 2026-09-30 · accessed 2026-09-30

tier 2 current vendor documentation

Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Profiles

Cisco Systems · 2026-04-25 · accessed 2026-09-25

tier 2 current vendor documentation

Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP TLS Support

Cisco · 2026-04-25 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SIP Trunk Monitoring

Cisco · 2026-04-25 · accessed 2026-09-24

tier 2 current vendor documentation

Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards - SRTP-SRTP Interworking

Cisco Systems · 2026-04-25 · accessed 2026-09-23

tier 2 current vendor documentation

Cisco Unified Border Element Configuration Guide - Cisco IOS XE 17.6 Onwards: ICE-Lite Support

Cisco · 2026-09-29 · accessed 2026-09-30

tier 2 current vendor documentation

Configure call routing for Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-21

tier 2 current vendor documentation

Connect your Session Border Controller (SBC) to Direct Routing

Microsoft · 2026-04-26 · accessed 2026-09-21

tier 2 current vendor documentation

Enable users for Direct Routing

Microsoft · 2026-08-21 · accessed 2026-09-21

tier 2 current vendor documentation

Health dashboard for Direct Routing

Microsoft · 2026-04-29 · accessed 2026-09-24

tier 2 current vendor documentation

Plan and manage emergency calling

Microsoft · 2026-03-23 · accessed 2026-09-16

tier 2 current vendor documentation

Plan Direct Routing

Microsoft (Microsoft Learn) · 2026-08-21 · accessed 2026-09-06

tier 2 current vendor documentation

Plan for media bypass with Direct Routing

Microsoft · 2026-09-10 · accessed 2026-09-16

tier 2 current vendor documentation

PSTN connectivity options

Microsoft (Microsoft Learn) · 2026-08-06 · accessed 2026-09-06

tier 2 current vendor documentation

Session Border Controllers certified for Direct Routing - Microsoft Teams

Microsoft · 2026-05-27 · accessed 2026-09-14

tier 2 current vendor documentation

SIP Dial Peer Configurations - IOS-XE VoIP

Cisco DevNet · 2026-09-30 · accessed 2026-09-30

tier 2 current vendor documentation

Teams Phone System Direct Routing: SIP protocol

Microsoft · 2026-08-21 · accessed 2026-09-23

tier 2 current vendor documentation

What's New Direct Routing

Microsoft · 2026-03-09 · accessed 2026-09-23

Cite this page

APA

WarmTransfer. (2026, September 30). Setting up CUBE as a Microsoft Teams Direct Routing SBC. WarmTransfer. https://warmtransfer.net/guides/cube-teams-direct-routing-setup

BibTeX

@misc{warmtransfer-cube-teams-direct-routing-setup,
  title  = {Setting up CUBE as a Microsoft Teams Direct Routing SBC},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/guides/cube-teams-direct-routing-setup},
  note   = {Verified 2026-09-30}
}