# MS teams first time call drop and get alert but next time for same call i didnt get alert - SID 2016150

**URL:** <https://forum.suricata.io/t/ms-teams-first-time-call-drop-and-get-alert-but-next-time-for-same-call-i-didnt-get-alert-sid-2016150/2007>\
**Category:** Help\
**Created:** [December 9, 2021, 3:01pm UTC](https://forum.suricata.io/t/ms-teams-first-time-call-drop-and-get-alert-but-next-time-for-same-call-i-didnt-get-alert-sid-2016150/2007 "2021-12-09T15:01:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vinayagamoorthym](https://avatars.discourse-cdn.com/v4/letter/v/fbc32d/32.png) [@vinayagamoorthym](https://forum.suricata.io/u/vinayagamoorthym)\
**Post date:** [December 9, 2021, 3:01pm UTC](https://forum.suricata.io/t/ms-teams-first-time-call-drop-and-get-alert-but-next-time-for-same-call-i-didnt-get-alert-sid-2016150/2007/1 "2021-12-09T15:01:48Z")

</div>

drop udp $EXTERNAL\_NET 3478 → $HOME\_NET **any (msg:“ET INFO Session Traversal Utilities for NAT (STUN Binding Response)”;** content:"|01 01|"; depth:2; content:"|21 12 a4 42|"; distance:2; within:4; reference:url,[tools.ietf.org/html/rfc5389;](http://tools.ietf.org/html/rfc5389;) **classtype:attempted-user** ; **sid:2016150** ; rev:2; metadata:created\_at 2013\_01\_04, updated\_at 2013\_01\_04;)

---

<div class="post-metadata">

**Author:** ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)\
**Post date:** [December 9, 2021, 9:58pm UTC](https://forum.suricata.io/t/ms-teams-first-time-call-drop-and-get-alert-but-next-time-for-same-call-i-didnt-get-alert-sid-2016150/2007/2 "2021-12-09T21:58:22Z")

</div>

You would have to check the actual traffic, ideally via pcap what difference is between the two attempts.

---

<div class="post-metadata">

**Author:** ![vinayagamoorthym](https://avatars.discourse-cdn.com/v4/letter/v/fbc32d/32.png) [@vinayagamoorthym](https://forum.suricata.io/u/vinayagamoorthym)\
**Post date:** [December 10, 2021, 4:32am UTC](https://forum.suricata.io/t/ms-teams-first-time-call-drop-and-get-alert-but-next-time-for-same-call-i-didnt-get-alert-sid-2016150/2007/3 "2021-12-10T04:32:15Z")

</div>

Thanks for your information Andreas… Will verify it…

---

<div class="post-metadata">

**Author:** ![Jungho](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jungho/32/397_2.png) [@Jungho](https://forum.suricata.io/u/Jungho)\
**Post date:** [December 11, 2021, 4:39pm UTC](https://forum.suricata.io/t/ms-teams-first-time-call-drop-and-get-alert-but-next-time-for-same-call-i-didnt-get-alert-sid-2016150/2007/4 "2021-12-11T16:39:32Z")

</div>

STUN behavior should also check whether it is working on TCP and for Classic STUN (RFC 3489). However, if the purpose is to block only Teams, it may be appropriate to identify the traffic generated for calls in Teams rather than STUN, which is a common protocol.
