Publishing Lync with Forefront TMG (part 4)
Skriven av
Silverdrake
,
26 April 2012
·
383 visningar
Publishing Lync Edge server with Forefront TMG
This is part 4 of 5 in a series that describes how to publish Lync Web Services and Lync Edge with a Microsoft Forefront TMG 2010 server.
Part 1 - Covers the initial configuration of Forefront TMG
Part 2 - Publishing Lync Web Services with Forefront TMG
Part 3 - Creating the protocols needed for publishing Lync Edge server
Part 4 - Publishing Lync Edge server with Forefront TMG
Part 5 - Installing Lync Front End and Lync Edge
Create the rules in Forefront TMG
Create Access Rule for Access Edge Outbound.
Name: Lync Access Edge Outbound
Select Allow
<a href="http://2.bp.blogspot...+1-763577.jpg">
Add these protocols.
Select Lync Access Edge as source
And external as destination
Click Publish Non-Web Server protocols
Name: Access Edge inbound HTTPS
Enter the Access Edge IP (on DMZ1)
Select HTTPS Server
Select the external interface and the external IP for your Access Edge role (10.0.0.10 in this case)
Run the Publish Non-Web Server wizard again
Name: Lync Access Edge SIP/MTLS Inbound
Enter the IP
Select the protocol Lync SIP/MTLS Server
Select the external interface and the Access Edge IP address
Run Publish Non-Web Server again
Name: Lync Webconf Edge Inbound HTTPS
Enter the Webconf Edge IP (on DMZ1)
http://4.bp.blogspot.com/-Sdgtd7dCZ4Y/T5bbMzZUVDI/AAAAAAAAAN4/0PqjV07pHYM/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B11-778848.jpg
Select HTTPS Server
http://1.bp.blogspot.com/-lUDiJMWQmW4/T5bbNUynJ7I/AAAAAAAAAOE/i0FtzwMPmZY/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B12-781576.jpg
Select the external interface and the external IP for Webconf Edge. (10.0.0.11)
Create a new Access Rule
Name: Lync A/V Edge 50K Range Outbound
Select Allow
http://2.bp.blogspot.com/-T8TV6zl8yik/T5bbOGsN3rI/AAAAAAAAAOQ/YZTxiKzsyUw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B13-784076.jpg
Select the protocol Lync TCP/UDS All and then click on Ports…
http://3.bp.blogspot.com/-wz0-nM0GFGU/T5bbOSsFlUI/AAAAAAAAAOc/Kq7wKXkc72Q/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B14-785348.jpg
Enter the range 50000 to 59999
http://2.bp.blogspot.com/-sgAxAItQsWU/T5bbO6ZaPkI/AAAAAAAAAOk/P5nDkeVeTW4/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B15-787195.jpg
Select Lync AV Edge as source
http://2.bp.blogspot.com/-s_NutvoU3IE/T5bbPAP1ghI/AAAAAAAAAOs/Mw9F4z5_Kfs/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B16-788149.jpg
And External as destination
Create a new Access Rule
Name: Lync A/V Edge STUN/MSTURN Outbound
Select Allow
http://2.bp.blogspot.com/-Rukq7IUFs9M/T5bbPSm4ZdI/AAAAAAAAAO4/18QwQ6TGa-Q/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B17-789260.jpg
Select the protocol Lync STUN/MSTURN and then click on Ports…
http://3.bp.blogspot.com/-pO7y5sGojfM/T5bbPiJMwwI/AAAAAAAAAPI/tlo0yAz-xj0/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B18-790139.jpg
Enter the 3478 as source port.
http://3.bp.blogspot.com/-lH9EP0lA03I/T5bbP2hnEGI/AAAAAAAAAPU/nDlNj3MIoVo/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B19-791346.jpg
Select Lync AV Edge as source
http://1.bp.blogspot.com/-p9i3S0E6bgU/T5bbQMrAE5I/AAAAAAAAAPg/hChJlLJVE8g/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B20-792597.jpg
And External as destination
Click Publish Non-Web Server
Name: Lync A/V Edge 50K Range Inbound
(This is only needed for federations with OCS2007)
http://1.bp.blogspot.com/-3wcmJtBH0RE/T5bbQaPH63I/AAAAAAAAAPs/d5iW3yoRpxc/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B21-793932.jpg
Enter the AV Edge IP (on DMZ1)
http://2.bp.blogspot.com/-9aSwrvTsBwU/T5bbQ3IuzPI/AAAAAAAAAP0/-FG6NVBv1pM/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B22-795244.jpg
Select the protocol Lync RTP 50K Range Server
http://3.bp.blogspot.com/-KVEXBFG_zoE/T5bbRAlqH0I/AAAAAAAAAQI/T7kUq3o4mM4/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B23-796351.jpg
Select the external interface and the external IP of your AV Edge role.
Click Publish Non-Web Server
Name: Lync A/V Edge STUN/MSTURN 3478
http://4.bp.blogspot.com/-E1IwBxX25AI/T5bbRpUd-QI/AAAAAAAAAQU/5QQgwlr2B2s/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B24-798356.jpg
Enter the AV Edge IP (on DMZ1)
http://1.bp.blogspot.com/-IHA0dxH9kjA/T5bbSCvgIdI/AAAAAAAAAQg/nHJsjp_1RyA/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B25-700107.jpg
Select Lync STUN/MSTURN Server
http://1.bp.blogspot.com/-Z--8DBJdHU4/T5bbSa5vWAI/AAAAAAAAAQs/i4zvXIY6p8Q/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B26-701889.jpg
Select the external interface and the IP for your AV Edge role
Click Publish Non-Web Server
Name: Lync A/V Edge STUN/MSTURN 443
http://1.bp.blogspot.com/-8JQ1GvqZBH0/T5bbSxvZj7I/AAAAAAAAAQ0/jAlzEvZshwU/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B27-703405.jpg
Enter the AV Edge IP (on DMZ1)
http://3.bp.blogspot.com/-CaO0A06xqLQ/T5bbTJS2_sI/AAAAAAAAARE/t1XRrbcN6ZU/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B28-704599.jpg
Select HTTPS Server
http://4.bp.blogspot.com/-J-fIB1F8IQc/T5bbTnXV13I/AAAAAAAAARQ/41YHTx1zDvc/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B29-706605.jpg
Select the external interface and the external IP for your AV Edge role
Create a new Access Rule
Name: Lync Edge Internal to Lync Front End
Select Allow
http://3.bp.blogspot.com/-rHOcBgKwPp8/T5bbUAreH8I/AAAAAAAAARc/at7r-dwFJFk/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B30-708151.jpg
Select the protocol Lync SIP/MTLS
http://2.bp.blogspot.com/-W0K9FtDDARk/T5bbUYUcQTI/AAAAAAAAARo/pidpD3Apsck/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B31-709162.jpg
Select Lync Edge Internal as source
http://4.bp.blogspot.com/-oFEUS5wrGtE/T5bbUgu93kI/AAAAAAAAAR0/_ogME2x7oOw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B32-710661.jpg
And Lync Front End as destination
Create a new Access Rule
Name: Lync Front End to Lync Edge
Select Allow
http://4.bp.blogspot.com/-I59VOOIvXac/T5bbUy20jcI/AAAAAAAAASA/C8oZDtqF0vw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B33-711609.jpg
Select the protocols Lync HTTPS 4443, Lync SIP/MTLS, Lync SIP/MTLS 5062
http://4.bp.blogspot.com/-HTjAG6v3kwc/T5bbVWryHDI/AAAAAAAAASM/yy6Slg3PxMY/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B34-713169.jpg
Select Lync Front End as source
http://4.bp.blogspot.com/-zpUHHTZBic4/T5bbVq_B3XI/AAAAAAAAASY/ClTwgHLoZlA/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B35-714618.jpg
And Lync Edge Internal as destination
Create a new Access Rule
Name: Internal to Lync Edge
Select Allow
http://3.bp.blogspot.com/-kpBI9TrrfAM/T5bbWHq6zuI/AAAAAAAAASo/E-uH5NvXIiY/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B36-716122.jpg
Select the protocols HTTPS, Lync PSOM/MTLS, Lync STUN/MSTURN
http://2.bp.blogspot.com/-XJw1k_3MlmI/T5bbWk0XebI/AAAAAAAAASw/mjh6z5-GMVs/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B37-718104.jpg
Select Internal as source
http://3.bp.blogspot.com/-spXLE9l1Fuk/T5bbXEXSfBI/AAAAAAAAAS8/i2KTemio4dw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B38-719845.jpg
And Lync Edge Internal as destinationIn the final part we will go through the setup of Lync Front End and Lync Edge
https://blogger.goog...ke.blogspot.com
Källa
This is part 4 of 5 in a series that describes how to publish Lync Web Services and Lync Edge with a Microsoft Forefront TMG 2010 server.
Part 1 - Covers the initial configuration of Forefront TMG
Part 2 - Publishing Lync Web Services with Forefront TMG
Part 3 - Creating the protocols needed for publishing Lync Edge server
Part 4 - Publishing Lync Edge server with Forefront TMG
Part 5 - Installing Lync Front End and Lync Edge
Create the rules in Forefront TMG
Create Access Rule for Access Edge Outbound.
Name: Lync Access Edge Outbound
Select Allow
<a href="http://2.bp.blogspot...+1-763577.jpg">
Add these protocols.
Select Lync Access Edge as source
And external as destination
Click Publish Non-Web Server protocols
Name: Access Edge inbound HTTPS
Enter the Access Edge IP (on DMZ1)
Select HTTPS Server
Select the external interface and the external IP for your Access Edge role (10.0.0.10 in this case)
Run the Publish Non-Web Server wizard again
Name: Lync Access Edge SIP/MTLS Inbound
Enter the IP
Select the protocol Lync SIP/MTLS Server
Select the external interface and the Access Edge IP address
Run Publish Non-Web Server again
Name: Lync Webconf Edge Inbound HTTPS
Enter the Webconf Edge IP (on DMZ1)
http://4.bp.blogspot.com/-Sdgtd7dCZ4Y/T5bbMzZUVDI/AAAAAAAAAN4/0PqjV07pHYM/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B11-778848.jpg
Select HTTPS Server
http://1.bp.blogspot.com/-lUDiJMWQmW4/T5bbNUynJ7I/AAAAAAAAAOE/i0FtzwMPmZY/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B12-781576.jpg
Select the external interface and the external IP for Webconf Edge. (10.0.0.11)
Create a new Access Rule
Name: Lync A/V Edge 50K Range Outbound
Select Allow
http://2.bp.blogspot.com/-T8TV6zl8yik/T5bbOGsN3rI/AAAAAAAAAOQ/YZTxiKzsyUw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B13-784076.jpg
Select the protocol Lync TCP/UDS All and then click on Ports…
http://3.bp.blogspot.com/-wz0-nM0GFGU/T5bbOSsFlUI/AAAAAAAAAOc/Kq7wKXkc72Q/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B14-785348.jpg
Enter the range 50000 to 59999
http://2.bp.blogspot.com/-sgAxAItQsWU/T5bbO6ZaPkI/AAAAAAAAAOk/P5nDkeVeTW4/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B15-787195.jpg
Select Lync AV Edge as source
http://2.bp.blogspot.com/-s_NutvoU3IE/T5bbPAP1ghI/AAAAAAAAAOs/Mw9F4z5_Kfs/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B16-788149.jpg
And External as destination
Create a new Access Rule
Name: Lync A/V Edge STUN/MSTURN Outbound
Select Allow
http://2.bp.blogspot.com/-Rukq7IUFs9M/T5bbPSm4ZdI/AAAAAAAAAO4/18QwQ6TGa-Q/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B17-789260.jpg
Select the protocol Lync STUN/MSTURN and then click on Ports…
http://3.bp.blogspot.com/-pO7y5sGojfM/T5bbPiJMwwI/AAAAAAAAAPI/tlo0yAz-xj0/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B18-790139.jpg
Enter the 3478 as source port.
http://3.bp.blogspot.com/-lH9EP0lA03I/T5bbP2hnEGI/AAAAAAAAAPU/nDlNj3MIoVo/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B19-791346.jpg
Select Lync AV Edge as source
http://1.bp.blogspot.com/-p9i3S0E6bgU/T5bbQMrAE5I/AAAAAAAAAPg/hChJlLJVE8g/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B20-792597.jpg
And External as destination
Click Publish Non-Web Server
Name: Lync A/V Edge 50K Range Inbound
(This is only needed for federations with OCS2007)
http://1.bp.blogspot.com/-3wcmJtBH0RE/T5bbQaPH63I/AAAAAAAAAPs/d5iW3yoRpxc/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B21-793932.jpg
Enter the AV Edge IP (on DMZ1)
http://2.bp.blogspot.com/-9aSwrvTsBwU/T5bbQ3IuzPI/AAAAAAAAAP0/-FG6NVBv1pM/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B22-795244.jpg
Select the protocol Lync RTP 50K Range Server
http://3.bp.blogspot.com/-KVEXBFG_zoE/T5bbRAlqH0I/AAAAAAAAAQI/T7kUq3o4mM4/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B23-796351.jpg
Select the external interface and the external IP of your AV Edge role.
Click Publish Non-Web Server
Name: Lync A/V Edge STUN/MSTURN 3478
http://4.bp.blogspot.com/-E1IwBxX25AI/T5bbRpUd-QI/AAAAAAAAAQU/5QQgwlr2B2s/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B24-798356.jpg
Enter the AV Edge IP (on DMZ1)
http://1.bp.blogspot.com/-IHA0dxH9kjA/T5bbSCvgIdI/AAAAAAAAAQg/nHJsjp_1RyA/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B25-700107.jpg
Select Lync STUN/MSTURN Server
http://1.bp.blogspot.com/-Z--8DBJdHU4/T5bbSa5vWAI/AAAAAAAAAQs/i4zvXIY6p8Q/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B26-701889.jpg
Select the external interface and the IP for your AV Edge role
Click Publish Non-Web Server
Name: Lync A/V Edge STUN/MSTURN 443
http://1.bp.blogspot.com/-8JQ1GvqZBH0/T5bbSxvZj7I/AAAAAAAAAQ0/jAlzEvZshwU/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B27-703405.jpg
Enter the AV Edge IP (on DMZ1)
http://3.bp.blogspot.com/-CaO0A06xqLQ/T5bbTJS2_sI/AAAAAAAAARE/t1XRrbcN6ZU/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B28-704599.jpg
Select HTTPS Server
http://4.bp.blogspot.com/-J-fIB1F8IQc/T5bbTnXV13I/AAAAAAAAARQ/41YHTx1zDvc/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B29-706605.jpg
Select the external interface and the external IP for your AV Edge role
Create a new Access Rule
Name: Lync Edge Internal to Lync Front End
Select Allow
http://3.bp.blogspot.com/-rHOcBgKwPp8/T5bbUAreH8I/AAAAAAAAARc/at7r-dwFJFk/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B30-708151.jpg
Select the protocol Lync SIP/MTLS
http://2.bp.blogspot.com/-W0K9FtDDARk/T5bbUYUcQTI/AAAAAAAAARo/pidpD3Apsck/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B31-709162.jpg
Select Lync Edge Internal as source
http://4.bp.blogspot.com/-oFEUS5wrGtE/T5bbUgu93kI/AAAAAAAAAR0/_ogME2x7oOw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B32-710661.jpg
And Lync Front End as destination
Create a new Access Rule
Name: Lync Front End to Lync Edge
Select Allow
http://4.bp.blogspot.com/-I59VOOIvXac/T5bbUy20jcI/AAAAAAAAASA/C8oZDtqF0vw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B33-711609.jpg
Select the protocols Lync HTTPS 4443, Lync SIP/MTLS, Lync SIP/MTLS 5062
http://4.bp.blogspot.com/-HTjAG6v3kwc/T5bbVWryHDI/AAAAAAAAASM/yy6Slg3PxMY/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B34-713169.jpg
Select Lync Front End as source
http://4.bp.blogspot.com/-zpUHHTZBic4/T5bbVq_B3XI/AAAAAAAAASY/ClTwgHLoZlA/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B35-714618.jpg
And Lync Edge Internal as destination
Create a new Access Rule
Name: Internal to Lync Edge
Select Allow
http://3.bp.blogspot.com/-kpBI9TrrfAM/T5bbWHq6zuI/AAAAAAAAASo/E-uH5NvXIiY/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B36-716122.jpg
Select the protocols HTTPS, Lync PSOM/MTLS, Lync STUN/MSTURN
http://2.bp.blogspot.com/-XJw1k_3MlmI/T5bbWk0XebI/AAAAAAAAASw/mjh6z5-GMVs/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B37-718104.jpg
Select Internal as source
http://3.bp.blogspot.com/-spXLE9l1Fuk/T5bbXEXSfBI/AAAAAAAAAS8/i2KTemio4dw/s320/Picture%2B%2528Device%2BIndependent%2BBitmap%2529%2B38-719845.jpg
And Lync Edge Internal as destinationIn the final part we will go through the setup of Lync Front End and Lync Edge
https://blogger.goog...ke.blogspot.com
Källa




Skapa anpassat tema


