Edge Servers

Office Communications Server 2007 R2 defines three Edge Server roles. These server roles are referred to as Edge Servers because they are deployed in the perimeter network of an organization’s network. These server roles enable an organization to expose Office Communications functionality across the corporate network boundary to remote employees, federated partners, and public IM connectivity users. Office Communications Server 2007 R2 exposes the following Edge Server roles:

  • Access Edge Server

  • Web Conferencing Edge Server

  • A/V Edge Server

These server roles are explained in more detail in the following sections. Hardware and software requirements for edge servers are shown in Table 3-5.

Table 3-5. Hardware and Software Requirements for Edge Servers

COMPONENT

REQUIREMENT

Computer and processor

64-bit, dual processor, dual core with 3.0-GHz or faster processor

Memory

8 GB or more of RAM recommended

Cache

1 MB L2 per core recommended

Hard disk

2 SCSI hard drives with 72 GB of available hard disk space recommended

Network

Two 1-gigabit NICs: one NIC for the external edge and the second NIC for the internal edge

Operating system (all 64-bit editions)

Windows Server 2008 Standard Edition, Windows Server 2003 Standard Edition, Windows Server 2003 R2 Standard Edition, or higher

Other

Public Key Certificates for Transport Layer Security (TLS), Active Directory domain/forest level Windows Server 2008, or Windows Server 2003

Access Edge Server

The Access Edge Server (formerly known as the Access Proxy in Live Communications Server 2005 SP1) must be deployed if you want to enable federation, public IM connectivity, or remote user access. The Access Edge Server handles the SIP traffic that is necessary to establish and validate connections. It does not transfer data or authenticate users. The Director, the internal Standard Edition Server, or the Enterprise pool authenticate users.

The Access Edge Server cannot be collocated with any other network perimeter service, such as Microsoft Internet Security and Acceleration (ISA) Server or the Microsoft Exchange 2007 Server Edge role; however, it can be collocated with the Web Conferencing Edge Server and the A/V Edge Server. In fact, the supported method of installing the Access Edge Server is along with the Web Conferencing and A/V Edge Server, all collocated on the same physical server known as the consolidated edge topology.

The Access Edge Server must be configured with two IP addresses, one that is visible to the Internet and one that is visible to the enterprise network. The recommended configuration (for performance and ease of securing the server) is to install two NICs, connecting the Internet to one and the enterprise network to the other. Access Edge Server configuration is discussed in further detail in Chapter 4.

To provide high availability in Office Communicator Server R2, consolidated Edge Servers can be deployed in the perimeter network. A hardware load balancer must be configured on both sides of the consolidated Edge Servers, as shown in Figure 3-7.

Array of Edge ServersNICs (network interface cards)Web Conferencing Edge ServersPSOM (Persistent Shared Object Model)Web Conferencing Edge ServersWeb Conferencing Edge ServersfunctionalityWeb Conferencing Edge ServersPSOM support

Figure 3-7. Array of Edge Servers

Web Conferencing Edge Server

The Web Conferencing Edge Server proxies PSOM Web conferencing media across the firewall between the Internet and the corporate network. The Web Conferencing Edge Server must be configured with two NICs: one network card connected to the Internet, and the other network card connected to the internal network. The network security administrator must open port 443 on the external NIC to allow users to connect from the Internet and port 8057 on the internal NIC so that Web Conferencing Servers can connect to it. Connections between the Web Conferencing Edge Server and the Web Conferencing Server are always initiated by the internal Web Conferencing Server. This design reduces the number of vectors into the corporate network.

If audio and video are not priorities for your edge deployment and high availability is still a concern, it is recommended that you combine the Access Edge Server role and the Web Conferencing Edge Server role on the same physical servers in an array with at least two physical servers. This configuration provides high availability while consolidating the number of Edge Servers required.

A/V Edge Server

The A/V Edge Server enables audio and video traffic to traverse the corporate perimeter network. The A/V Edge Server serves as a meeting point for bridging users connecting from the Internet to an A/V Conferencing Server associated with the user’s home server. Users connect to the A/V Edge Server, and the A/V Conferencing Server connects to the A/V Edge Server. The A/V Edge Server relays the Real-Time Protocol (RTP) traffic between the users and A/V Conferencing Server. Similar to the other Edge Server roles, the A/V Edge Server must be configured with two NICs: one network card connected directly to the Internet and given a public routable IP address, and the other network card connected to the internal network. The A/V Edge Server uses the Information and Content Exchange (ICE) protocol to enable clients to traverse firewalls that might lie between the end user’s client and the A/V Edge Server. A/V Edge Server configuration is discussed in further detail in Chapter 4.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset