Yes, from the Edge properties (via COMPMGMT.msc), I see...
It is the internal FQDN:5061 for the Access Edge internal authentication port
It is the FQDN:5062 for the A/V Edge internal authentication port
Then from the front-end, I verified that the A/V Authentication service is that same internal FQDN:5062
One thing, the internal interface on the EDGE has the internal CA certificate to the FQDN, and yes the root CA certificate is imported.
For the A/V Authentication certificate, I have the SN set to the external FQDN for the AV.domain.com DNS name of that interface, based on instructions from Microsoft's Edge planning tool for OCS 2007 R2
I can telnet from the internet via port 443 to the sip.domain, av.domain, lm.domain EDGE interfaces
I can telnet from the Edge server to the front-end on 5061 both via pool FQDN and server FQDN
I can telnet from the front-end server to the Edge server on 443, 5061, and 5062.





by: gaanthonyPosted on 2009-11-03 at 15:05:14ID: 25734885
On your OCS Forest Global Properties/Edge Servers tab you have the Access Edge server entry which would be the FQDN of your Access Edge Internal interface.
Under the AV Edge it should be the same here on port 5062 for a consolidated edge.
Therefore the certificates assigned to Edge Internal and AV auth on the edge should just be an internally issued cert with just subject name of the Edge internal interface with NO Subject Alternative names specified.
On the internal tab of the Edge server properites you need the Pool FQDN along with Front End FQDNs listed in authorized list of server that can connect ot the Edge.
You should be able to telnet the Pool FQDN from the Edge on port 5061.
You should be able to telnet the Edge Internal FQDN from the Front End/Pool server on port 5061, 5062, and 443.
The Edge doesn't get the Root certificate/chain from an internal CA since it's not domain joined. You have to import the chain there