,

Firewall Configuration

When planning a Lync Server environment, any remote access or federation features require significant firewall configuration to ensure the features work correctly and to properly secure the infrastructure. Many different firewall vendors, devices, and configurations can be used to achieve the goal.

The key points to keep in mind are as follows:

• The Edge Server has two network adapters to account for, and two different sets of rules must be created.

• The Edge Server requires at least two network adapters. One is internal facing and communicates with the internal Front-End Servers, Directors, and clients, and the second adapter communicates with the external traffic from the Internet.

Organizations might have a dedicated network security team that is different from the team responsible for implementing and managing Lync Server. Because the deployment planning typically crosses different teams, it is important for all parties to meet early in the planning stages to discuss the deployment requirements. Much of the work and troubleshooting with Edge Server firewall configuration is a collaborative effort between multiple teams to ensure each component is configured correctly.

The following section discusses the different firewall topologies that can be used for Lync Server and key considerations for each design.


Tip

It is highly recommended you place Edge Servers in a perimeter or DMZ network where they can be secured both from the Internet and internal network. This design allows the Edge Server to operate as designed—in a secure manner with limited exposure externally and a limited ability to impact internal operations.


..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset