This blog post should show you the communications ports between Skype for Business Frontend Servers and Clients and other servers involved in Skype communication.

Edge External
SourceDestinationDirectionDestination PortProtocolDescription
Edge Internal IPSfB Front EndInbound5061TCPOutbound SIP traffic from your Director, Director pool, Front End Server or Front End pool to your Edge Server internal interface.
SfB Front EndEdge Internal IPOutbound5061TCPOutbound SIP traffic from your Director, Director pool, Front End Server or Front End pool to your Edge Server internal interface.
8057TCPWeb conferencing traffic from your Front End Server or each Front End Server (if you have a Front End pool) to your Edge Server internal interface
5062TCPAuthentication of A/V users from your Front End Server or Front End pool, or your Survivable Branch Appliance or Survivable Branch Server, using your Edge Server.
4443TCPReplication of changes from your Central Management store to your Edge Server.
50001 – 50003TCPCentralized Logging Service controller using Skype for Business Server Management Shell and Centralized Logging Service cmdlets, ClsController command line (ClsController.exe) or agent (ClsAgent.exe) commands and log collection.
3478UDPPreferred path for A/V media transfer between your internal and external users and your Survivable Branch Appliance or Survivable Branch Server.
443TCPFallback path for A/V media transfer between your internal and external users and your Survivable Branch Appliance or Survivable Branch Server, if UDP communication doesn’t work. TCP is then used for file transfers and desktop sharing.
Mediation ServerSfB Front EndInbound5061TCPSIP / TLS
5070TCPUsed by the Mediation Server for incoming requests from the Front End Server
49152 – 57500TCP / UDPSRTP / RTCP
SfB Front EndMediation ServerOutbound5061TCPSIP / TLS
5070TCP / UDPUsed by the Mediation Server for incoming requests from the Front End Server
49152 – 57500TCP / UDPSRTP / RTCP
3478UDPSTUN
443TCP / UDPSTUN
445TCPReplication of changes from your Central Management store to Mediation through SMB 
ClientSfB Front EndInbound5061UDPSIP
443TCPHTTPS
80TCP HTTP
3478UDPThis is used for relaying media traffic
448TCPUsed for call admission control by the Skype for Business Server Bandwidth Policy Service.
8057TCP / UDPUsed to listen for Persistent Shared Object Model (PSOM) connections from client.
49152 – 65535TCP / UDPRTP / SRTP A/V / Webconf / AppSharing
SfB Front EndClientOutbound3478UDPSTUN/TURN negotiation of candidates over UDP on port 3478
SfB Front EndSQL BackendOutbound1433TCPSQL Connection Default Port
1434UDPEventually necessary when using named instances.
SfB Front EndOffice Online ServerOutbound443TCPOffice Online Server
SfB Front EndFile ShareOutbound445TCPSMB to Server with Skype SMB Share
Exchange ServerSfB Front EndInbound5061TCPSIP
SfB Front EndExchange ServerOutbound5061TCPSIP (Client Access server – Microsoft Unified Messaging Call Router service)
443TCPSTUN
3478UDPSTUN

Remarks:

  • The effectively needed ports on the high port range 49152 – 65535 may be different if you choose to restrict Audio, Video and App Sharing ports to some smaller range.
  • If you find any mistake or have questions feel free to comment.