Problem Description :

Coronavirus has become a global catastrophe and many organizations are encouraging work from home to avoid spreading it. This has caused many organizations to review their vpn infrastructure because if a whole organization starts doing WFH at once then it could cause many scalability issues because in most of organizations VPNs aren’t designed to work for the whole organization at once.

Let’s come to the point, Microsoft Office 365 is one of the primary workloads of organization and most of the organizations don’t care about intentionally force its traffic to be routed through VPN.

Microsoft recently published an article about split tunneling of Office 365 traffic so that when end-user connects to VPN, there office 365 isn’t routed through VPN instead, it is routed from user computer to internet directly. This will help in avoiding a large workload to consume VPN infrastructure.

Leverage split tunneling if your VPN product supports it.

Talk to your Network Engineers and Enable split tunneling for these office 365 FQDNs :

Endpoint to OptimizePort/sUse
https://outlook.office365.comTCP 443This is one of the Core URLs Outlook uses to connect to its Exchange Online server and has high volume of bandwidth usage and connection count. Low network latency is required for online features including: Instant search, Other mailbox calendars, Free / busy lookup, manage rules & alerts, Exchange online archive, Emails departing the outbox.
https://outlook.office.comTCP 443This is use for Outlook Online web access to connect to its Exchange Online server and network latency. Connectivity is particularly required for large file upload and download with SharePoint Online.
https://<tenant>.sharepoint.comTCP 443This is the primary URL for SharePoint Online and has high volume of bandwidth usage.
https://<tenant>-my.sharepoint.comTCP 443This is the primary URL for OneDrive for Business and has high volume of bandwidth and possibly high connection count from the OneDrive for Business Sync tool.
Teams Media IPs (no URL)UDP 3478, 3479, 3480, and 3481Relay Discovery allocation and real time traffic (3478), Audio (3479), Video (3480), and Video Screen Sharing (3481). These are the endpoints used for Skype for Business and Microsoft Teams Media traffic (Calls, meetings etc). Most endpoints are provided when the Microsoft Teams client establishes a call (and are contained within the required IPs listed for the service).UDP is required for optimal media quality.

Ref Articles

Thank you for reading and keep yourself safe !

Advertisement