Skip to main content
nflnetwork29
Explorer III
September 9, 2025
Question

Force Teams Voice out ISP2 & prioritize on 60F

  • September 9, 2025
  • 3 replies
  • 540 views

Hi,

On a standalone FortiGate 60F (FortiOS 7.4.7) with two WAN links (ISP1 = backup, ISP2 = primary), I need to:

  1. Force all Microsoft Teams voice/media traffic (UDP 3478–3481, 50000–50059) out ISP2, with ISP1 only as failover.

  2. Give Teams voice higher priority than other traffic.

What’s the best approach on this platform — SD-WAN service rules or router policies — and how should QoS/traffic shaping be set up?

Thanks!

3 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
September 11, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
September 12, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
September 15, 2025

Hello nflnetwork29,

 

I found this solution. Can you tell us if it helps, please?

 

To achieve your requirements on a FortiGate 60F with FortiOS 7.4.7, you can use SD-WAN service rules and traffic shaping. Here's a step-by-step approach:

 

  1. Configure SD-WAN:
    - Add both ISP1 and ISP2 to the SD-WAN interface.
    - Set ISP2 as the primary link and ISP1 as the backup.

  2. Create SD-WAN Service Rules:
    - Define a new SD-WAN rule for Microsoft Teams traffic.
    - Specify the source and destination addresses, and the UDP ports (3478–3481, 50000–50059). - Set the preferred interface to ISP2 and configure failover to ISP1.

  3. Configure Traffic Shaping:
    - Create a traffic shaping profile for Microsoft Teams.
    - Assign a higher priority to this profile to ensure Teams voice traffic is prioritized over other traffic.
    - Apply this traffic shaping profile to the SD-WAN rule for Microsoft Teams.

  4. Set Up Firewall Policies:
    - Create firewall policies to allow Microsoft Teams traffic from the internal network to the internet.
    - Ensure these policies are aligned with the SD-WAN rules and traffic shaping profiles.

  5. Testing and Monitoring:
    - Simulate failover scenarios to ensure traffic is correctly routed through ISP2 and fails over to ISP1 when necessary.
    - Monitor traffic to verify that Teams voice traffic is prioritized.

 

By using SD-WAN service rules, you can effectively manage the routing and prioritization of Microsoft Teams traffic, ensuring it uses the primary link and has higher priority.

Jean-Philippe - Fortinet Community Team
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!