Installing Lync Edge server

Posted on 2012-04-06
Last Modified: 2012-08-13
I just read this for LYNC EDGE SERVER :
Two interfaces required, either one 2-port 1 Gbps NIC or two 1-port 1 Gbps NICs.

So I guess one is for internal LAN and one is for the DMZ.
1. Is it really necessary to have 2 NICs ?
2. Does the DMZ nic has to be able to access the internet ? and if so how do I do this on eg a DLINK DFL-160 (if I try it with my laptop and connect the lancable to the LAN and my laptop to the DMZ I cannot access the internet at this moment)
Question by:troosters
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Expert Comment

ID: 37815541
Lync is a very complex system to configure, but it is quite fully featured and worth the effort.

You will definitely need 2 NICs.

The DMZ interface connects to your Lync Front End server. The Internet traffic to your Lync system will go to your Edge server, it will then 'proxy' that traffic to your Front End server through the DNZ.

You will also need an application level firewall act as a reverse-proxy.  (A quick Google search doesn't look like the DFL-160 can do this).

This blog helped me the first time I configured Lync:

If you've got other questions, send them through.


Author Comment

ID: 37815618
So what you are saying is I should connect my FE to the DMZ connection on the firewall and the EDGE server to 2 LANports on the firewall ??

Here is my situation now. I have a SBS2011 server on which I installed a virtual server with HYPER-V which is my LYNC FE server. I can make calls with LYNC now.
But I have no idea how to go further, and I have never installed a DMZ before.

Expert Comment

ID: 37815650
I don't really know how your firewall is configured, but the general idea is this:
Internet connection >> NAT (port forwarding) >>IP address of Edge on one NIC >> The server proxies traffic through>>second NIC >> Front end server.

The idea is that the DMZ NIC on a different subnet to your normal internal LAN connection.

Any systems that involve a large number of 'open' ports or SIP traffic (namely phone systems) can be a security concern. So, I would definitely recommend running this in detail by a networking guy if you have access to one.

I've also attached a doco that outlines what traffic is needed for different features. Some features do not need the reverse-proxy.
What features are you ultimately wanting to use?

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Expert Comment

ID: 37816284
Just as a small addition, Josh you are totally right by the way, even if you are not using the roles which use a reverse proxy now, I still recommend putting it in place in the event that you choose to expand, it is already in a configured.

Author Comment

ID: 37816312
Is it not also possible to install the edge without the DMZ just for testing (demowise) ?

Accepted Solution

Joshua1909 earned 500 total points
ID: 37820130
I have gotten Lync working without a DMZ for testing, but it only worked internal to the site and is definitely not officially supported.


Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Implementing Avaya's One-X portal is pretty painless, until you want to deploy this to the Android and iPhone clients when these clients are outside of your network. The clients will also work within your local network. Here is our experience and so…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question