Network-Based Firewalls

Most implementations of Lync Server involve some form of a network-based firewall, usually in the DMZ (demilitarized zone). The purpose of this device is to ensure that only the necessary services on the Lync Server systems are made available externally.

To maximize security, it is fairly common to configure the external services of Lync Server so that not only is there a firewall between the Internet and the Lync Server servers, but there also is a firewall between the internal network and the Lync Server servers. This can be accomplished either with dual firewalls or by placing the Lync Server servers into a DMZ on a three-or-more-legged firewall. Dual firewalls are technically more secure because if an attacker compromised the firewall that was exposed externally, he would still have to compromise a second firewall before having access to the internal hosts.

The first step in implementing this type of firewall for Lync Server is to understand what services you plan to make available from outside the network and then to determine exactly which ports and protocols need to be opened on the firewall.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset