Link to home
Start Free TrialLog in
Avatar of M A
M AFlag for United States of America

asked on

Use lync outside the network

I have installed lync2010 and is working perfectly from inside the org.
Now I need important users to connect to lync when they are out.

Without edge is possible? without edge is recommended?
As of now I am using my internal CA certificate.
Avatar of Radhakrishnan
Radhakrishnan
Flag of India image

Without edge interface you will be not install the certificate for external linc access.
Have a look at this MS article which detsils the steps
technet.microsoft.com/en-us/library/gg398409.aspx
Avatar of M A

ASKER

You mean I have to install Lync on another hardware?
If only you have multiple edge severs, You should purchase a public certificate for external access and import this on each edge server.
Avatar of M A

ASKER

As of now I have only one server.
what all things I have to do to make it available from outside (except NAT in firewall)
Purchase a public certificate and install it as per the tech article. Then it will be accessible externally.
Avatar of M A

ASKER

How lync client will reach the server. Using what name?
servername.internaldomain.com
or
I have to configure external name ?
Obviously it should be external one for external access.
Avatar of M A

ASKER

Where Io will configure external name in such a way a user go out from office and open laptop it should work.
Avatar of M A

ASKER

Where I will configure external name in such a way a user go out from office and open laptop it from outside and it works?
Yes, it will work
Avatar of M A

ASKER

Where I will configure external name?
You can can configure the server and the certificate should be https://servername.yourpublicdomain.com
Avatar of M A

ASKER

"The server is not responding or cannot be reached...."
This is the error I get when I try to login from outside

What could be wrong
Avatar of M A

ASKER

Now getting this error.
Your help is appreciated to finish this question
error.png
Could you add the site into trusted list from IE and provide admin credentials to login.
Ensure that the logon users are member os Csadministrator group in AD.
Also, check the dns entries whether its present.
Avatar of M A

ASKER

It is only working with internal servername/IP
It is not working with external servername/IP

From internal network I configured internal and external name. it is working
But outside network it is not working. when I connect VPN from outside it is working with the internal name

What shall I do to make it working from outside with the external name?
The name should be configure in the certificate.
Avatar of M A

ASKER

It is already configured
Avatar of M A

ASKER

BTW
SIP domain is internal domain name (i.e. xyz.com)
external FQDN is abc.com (I added this as additional SIP domain)
Avatar of M A

ASKER

Now I added SRV records (_kpasswd, _ldap, _gc) now it is working with external name from inside.

Do I have to create SRV records in external DNS?
The host A record would be sufficient, since it's working internally after adding the srv records, it's worth to try creating a srv record.
Avatar of M A

ASKER

_internaltls._tcp.externalname.com
or
_sip._tls.externalname.com
?
Its sip.tls.externalname.com
Avatar of M A

ASKER

I have created SRV records same like as in internal DNS but still no luck.
SOLUTION
Avatar of Radhakrishnan
Radhakrishnan
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of M A

ASKER

Do you know how it works from outside?
So that I can check and trouble shoot in a short time.
Avatar of M A

ASKER

Please help it is not working from outside
Any thought of connecting the users to a VPN internally and then they should be able to connect as if they were in the office..have many customers set up this way.
Avatar of M A

ASKER

Already users connected through VPN from outside. I want users to connect without vpn from outside.
Avatar of M A

ASKER

awaiting your reply
I think the only way to connect without VPN is either to setup a reverse proxy (have seen customers do this, essentially publish Lynch on the DMZ) or have everyone register with an outiside entity such as Microsoft.
Avatar of M A

ASKER

how to setup reverse proxy
I do not have DMZ
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of M A

ASKER

I have managed to work from outside by doing a port forwarding from 8080/4443 to 80/443
but no audio and video calls can you help to configure
Avatar of M A

ASKER

I found another site to configure without reverse proxy
Avatar of FarrellFritz
FarrellFritz

I am interested in comments by abbasiftt.  I have thus far been unable to get it working via VPN (this should be easier).

Getting "There was a problem verifying the certificate from the server"

From what I've read it's been suggested that I manually import the certificate from the server to the VPN client.  No problem but cannot identify which cert is the one (for Lync) I should be exporting/importing?

Is this the right suggestion?  If so, how do I identify which cert to import?