Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Installing Lync Edge server

Posted on 2012-04-06
6
Medium Priority
?
770 Views
Last Modified: 2012-08-13
Hi,
I just read this for LYNC EDGE SERVER :
Two interfaces required, either one 2-port 1 Gbps NIC or two 1-port 1 Gbps NICs.

So I guess one is for internal LAN and one is for the DMZ.
1. Is it really necessary to have 2 NICs ?
2. Does the DMZ nic has to be able to access the internet ? and if so how do I do this on eg a DLINK DFL-160 (if I try it with my laptop and connect the lancable to the LAN and my laptop to the DMZ I cannot access the internet at this moment)
0
Comment
Question by:troosters
  • 3
  • 2
6 Comments
 
LVL 6

Expert Comment

by:Joshua1909
ID: 37815541
Hi,
Lync is a very complex system to configure, but it is quite fully featured and worth the effort.

You will definitely need 2 NICs.

The DMZ interface connects to your Lync Front End server. The Internet traffic to your Lync system will go to your Edge server, it will then 'proxy' that traffic to your Front End server through the DNZ.

You will also need an application level firewall act as a reverse-proxy.  (A quick Google search doesn't look like the DFL-160 can do this).


This blog helped me the first time I configured Lync:
http://ocsguy.com/2010/09/13/welcome-to-lync/


If you've got other questions, send them through.

Cheers,
Josh
0
 

Author Comment

by:troosters
ID: 37815618
So what you are saying is I should connect my FE to the DMZ connection on the firewall and the EDGE server to 2 LANports on the firewall ??

Here is my situation now. I have a SBS2011 server on which I installed a virtual server with HYPER-V which is my LYNC FE server. I can make calls with LYNC now.
But I have no idea how to go further, and I have never installed a DMZ before.
0
 
LVL 6

Expert Comment

by:Joshua1909
ID: 37815650
I don't really know how your firewall is configured, but the general idea is this:
Internet connection >> NAT (port forwarding) >>IP address of Edge on one NIC >> The server proxies traffic through>>second NIC >> Front end server.

The idea is that the DMZ NIC on a different subnet to your normal internal LAN connection.

Any systems that involve a large number of 'open' ports or SIP traffic (namely phone systems) can be a security concern. So, I would definitely recommend running this in detail by a networking guy if you have access to one.

I've also attached a doco that outlines what traffic is needed for different features. Some features do not need the reverse-proxy.
What features are you ultimately wanting to use?


Cheers,
Josh
Microsoft-Lync-Server-2010-Proto.pdf
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 8

Expert Comment

by:djjackfrwmml
ID: 37816284
Just as a small addition, Josh you are totally right by the way, even if you are not using the roles which use a reverse proxy now, I still recommend putting it in place in the event that you choose to expand, it is already in a configured.
0
 

Author Comment

by:troosters
ID: 37816312
Is it not also possible to install the edge without the DMZ just for testing (demowise) ?
0
 
LVL 6

Accepted Solution

by:
Joshua1909 earned 2000 total points
ID: 37820130
Hi,
I have gotten Lync working without a DMZ for testing, but it only worked internal to the site and is definitely not officially supported.

http://social.technet.microsoft.com/Forums/en-US/ocsedge/thread/3f37324b-d1db-477a-a2a2-6ff9fc85e105/

Cheers,
Josh
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As companies replace their old PBX phone systems with Unified IP Communications, many are finding out that legacy applications such as fax do not work well with VoIP. Fortunately, Cloud Faxing provides a cost-effective alternative that works over an…
A safe way to clean winsxs folder from your windows server 2008 R2 editions
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question