440 likes | 454 Views
Learn the essential strategies to optimize your network for Microsoft Teams, including addressing firewall and proxy issues, fixing VPN and delay problems, and implementing QoS and internal firewall settings.
E N D
Top five things you need to know to optimize your network for Microsoft Teams Johan Delimon Chief Solutions Architect, MVP Skype for Business &Teams The Collective, idelimon BVBA, GGEHOSTED, Ordina, Fujitsu THR3081
Johan Delimon Johan Delimon idelimon BVBA / johan@delimon.be / @jdelimon / Skype for Business MVP / MCSM Communications / Skype4B Architect The Collective / idelimon BVBA / johan@delimon.be / @jdelimon / Skype4B - Teams MVP / MCSM Communications / Skype4B Architect
Pre Internet Age HQ Corporate Network
Starting Internet Age Reasons for Firewall & Proxy • Security • Control • Compliance • … Internet Firewall Proxy HQ Corporate Network
Trust in Early Internet Age Internet Firewall Proxy HQ Corporate Network
Extending Internet to Corp Internet VPN Concentrator Firewall Proxy HQ Corporate Network
Extending Internet to Corp Reasons for Firewall & Proxy • Security • Control • Compliance • … Internet VPN Concentrator Firewall Proxy HQ Corporate Network
Cloud Era VPN Concentrator Firewall Proxy HQ Remote Site Corporate Network
Cloud Era VPN Concentrator Firewall Proxy HQ Remote Site Corporate Network
Cloud Era VPN Concentrator Firewall Proxy HQ Remote Site Corporate Network
Cloud Era Internet Connection VPN Concentrator Firewall Proxy HQ Corporate Network
Problems with this setup • Proxy Servers (HTTP Only TCP 80 & 443) • Firewalls only allow Proxy Servers to Internet • VPN used for Internet Access • Remote Offices use Central Internet Breakout • Office 365 is not a trusted destination
Proxy Servers Problem #1
Fix Proxy Solutions • Remove Proxy all together • Get proper exceptions in place Firewalls may still block users from connecting VPN Concentrator Firewall Proxy HQ Remote Site Corporate Network
Howto Fix Proxy • PROXY.PAC file to exclude all Office 365 URLs from Proxy • Configure Exceptions in browser (GPO) • Direct connection to Internet for Office 365 URLs • Firewall may still block connections • URLs change all the time Get Updates for URLs here Office 365 URLs and IP address ranges https://docs.microsoft.com/en-us/office365/enterprise/urls-and-ip-address-ranges Office 365 IP Address and URL Web service https://docs.microsoft.com/en-us/office365/enterprise/office-365-ip-web-service
Firewalls Problem #2
Fix Firewalls Solution • Allow all Office 365 Ips • Allow all required Ports VPN Concentrator Firewall Proxy HQ Remote Site Corporate Network
Howto Fix Firewalls • Allow all Office 365 IPs • Allow all required Ports • Express Route for corner case scenario’s Get Updates for IPs and Ports Office 365 URLs and IP address ranges https://docs.microsoft.com/en-us/office365/enterprise/urls-and-ip-address-ranges Office 365 IP Address and URL Web service https://docs.microsoft.com/en-us/office365/enterprise/office-365-ip-web-service
Office 365 URLs and IP address ranges Microsoft Teams Ports
VPN Problem #3
Fix VPNs Solution • Require Split Tunnel VPN • Exclude all Office 365 IPs from VPN Tunnel VPN Concentrator Firewall Proxy HQ Remote Site Corporate Network
Howto Fix VPNs • Requires Split Tunneling • Allow all Office 365 URLs • Allow all Office 365 IPs • Allow all required Ports Get Updates for URLs, IPs and Ports Office 365 URLs and IP address ranges https://docs.microsoft.com/en-us/office365/enterprise/urls-and-ip-address-ranges Office 365 IP Address and URL Web service https://docs.microsoft.com/en-us/office365/enterprise/office-365-ip-web-service
Trust Office 365 Office 365 is now a trusted source and destination Extension of you Corporate Network now include Office 365 VPN Concentrator Firewall Proxy HQ Remote Site Corporate Network
Roundtrip Delay / Internet Breakout Problem #4
Delay Microsoft Global Network Transport Relays Internet Firewall Proxy HQ Remote Site Corporate Network
Delay Microsoft Global Network Transport Relays Internet Firewall Proxy Firewall HQ Remote Site Corporate Network
Howto Fix Delays • Local Breakout in every Location • Direct Peering with Microsoft (ISP) • Express Route for corner case scenario’s
Skype for Business & Microsoft Teams Network Assessment Tool https://www.microsoft.com/en-us/download/details.aspx?id=53885
Network Assessment Microsoft Global Network Transport Relays Internet Network EDGE Network EDGE Client Machine Client Machine Site Site
Client & Customer Network Edge performance requirements to Microsoft network Edge
QoS & Internal Firewalls Problem #5
Fix QoS & Internal Firewalls Transport Relays Firewall Proxy Firewall HQ Remote Site Corporate Network
Fix QoS & Internal Firewalls Transport Relays Firewall Proxy Firewall HQ Remote Site Corporate Network
Fix Internal Firewalls & QoS • Understand Client Port Ranges in Use • Allow Client port Ranges in Firwall for P2P communication • Setup GPO’s for QoS for both Skype for Business • Client Port ranges cannot be changed (May Change in the Future)
Please evaluate this sessionYour feedback is important to us! Please evaluate this session through MyEvaluations on the mobile appor website. Download the app:https://aka.ms/ignite.mobileApp Go to the website: https://myignite.techcommunity.microsoft.com/evaluations