SlideShare a Scribd company logo
1 of 1
Download to read offline
LEGEND
Enterprise poolHardware
load balancer
Edge Servers
Front End Servers
SQL back-end server
Directors
Communicator Web
Access Server
Archiving Server
Monitoring Server Group Chat Server
Update Server
Exchange UM Server
Mediation Server XMPP gatewayReverse proxy
© 2009 Microsoft Corporation. Active Directory, Office, MSN, and any associated logos are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. All rights reserved. Other trademarks or trade names mentioned herein are the property of their respective owners.
Workload Architecture
http://twitter.com/DrRezhttp://TechNet.microsoft.com/office/OCS http://go.microsoft.com/fwlink/?LinkId=181907
Multi-NIC support
CERTIFICATE REQUIREMENTS
Communicator
Phone Edition
Office Live MeetingOffice Communicator Attendant Console
Communicator
Web Access
CLIENTS
SIP/TLS:443
Edge
Servers
External
Firewall
Internal
Firewall
Directors
XMPP
Gateway
Edge
Servers
External
firewall
Internal
firewall
RTP/SRTP traffic
IM and Presence Workload
A/V and Web Conferencing Workload Enterprise Voice Workload
HTTPS:443
C3P/HTTPS:444
SIP/MTLS:5061
Application Sharing Workload
XMPP/TCP:5269
Pools
Connectivity to:
• IP-PSTN
gateway
• IP/PBX
• Direct SIP
• SIP trunk
Pools
Reverse proxy
Access Edge - SIP/MTLS:5061Federated
Company
Yahoo!
MSN
AOL
Jabber
Gmail
HTTPS:443
A/V Edge - STUN/TCP:443, STUN/UDP:3478
Access Edge - SIP/TLS:443
A/V Edge – SRTP:443,3478,50,000-59,999
SIP/MTLS:5061
HTTPS:443
Access Edge - SIP/TLS:443
SIP/MTLS:5061
HTTPS:443
SRTP/RTCP:60,000-64,000
SIP/TLS:5061
SIP traffic
External
firewall
Internal
firewall
HTTPS:443
Communicator
Web Access
Server
HTTPS:443
Pools
A/V Edge – SRTP:443,3478,50,000-59,999
HTTPS:443
SRTP/RTCP:60,000-64,000
Access Edge - SIP/TLS:443
SIP/MTLS:5061
Edge
Servers
External
firewall
Internal
firewall
HTTPS:443
Reverse proxy
HTTPS traffic HTTPS:443
Pools
HTTPS:443
SIP traffic: signaling
SIP/MTLS:5061
SIP/TLS:5061
RTP/SRTP traffic: A/V Conferencing
A/V Edge - STUN/TCP:443, STUN/UDP:3478
A/V Edge – SRTP:443,3478,50,000-59,999
SRTP/UDP:49152-65535
This media traffic goes directly to
the A/V Edge. The A/V Edge
must have publicly routable IP
addresses
If using a single Edge Server, the
public Edge IP addresses can be
NAT-ed by your external firewall.
Range of ports
is configurable
RDP/SRTP traffic
HTTPS traffic
SIP traffic
SIP traffic: signaling and IM
XMPP traffic
HTTPS traffic
MSMQ traffic
SIP/MTLS:5062
PSOM traffic: Web Conferencing
HTTPS:443 is used to download
address book and updates
Communicator
Mobile
Group Chat
Group Chat file share
Address book file share
Group Chat
Compliance
Server
Meeting content
+ metadata +
compliance file
share
PSOM/TLS:8057
HTTPS:443
HTTPS:443
HTTPS:443 is used
to download
conferencing
content + metadata
Media codec varies
on workload:
- RTAudio
- G.711
Traffic goes directly to Web
Conferencing Service
WITHOUT going through the
pool’s hardware load balancer
2 inbound and 2 outbound
unidirectional streams.
Media codec varies on workload:
- RTAudio for audio
- RTVideo for video
Range of ports
is configurable
SRTP consists of two
unidirectional streams. RTCP
traffic piggy backs on the SRTP
stream.
Media codec varies on workload:
- RTAudio
- G.711
SIP/TLS:5061
SRVquery
(1)
(3)
Range of ports
is configurable
Traffic goes directly to A/V
Conferencing Service
WITHOUT going through the
pool’s hardware load balancer
Mediation Server
FQDN: medsrv.<ad-domain>
Certificate SN: medsrv.<ad-domain>
Certificate SAN: N/A
EKU: server
Root certificate: private CA
Exchange UM Server
FQDN: umsrv.<ad-domain>
Certificate SN: umsrv.<ad-domain>
Certificate SAN: N/A
EKU: server
Root certificate: private CA
Directors
Front End Server 1, Front End Server 2
FQDN: pool.<ad-domain>
Certificate SN: pool.<ad-domain>
Certificate SAN: pool.<ad-domain>,
EKU: server
Root certificate: private CA
Pool
Director 1, Director 2
FQDN: dir.<ad-domain>
Certificate SN: dir.<ad-domain>
Certificate SAN: dir.<ad-domain>,
sipinternal.<sip-domain>
EKU: server
Root certificate: private CA
STUN/TCP:443, STUN/UDP:3478
Mediation Server
External user sign-in process:
1. Client resolves DNS SRV record _sip._tls.<sip-domain> to Edge Server.
2. Client connects to Edge Server.
3. Edge Server proxies connection to Director.
4. Director authenticates user and proxies connection to user’s home pool.
FQDN: xmppsrv.<sip-domain> (1)
Certificate SN: xmppsrv.<sip-domain>
Certificate SAN: N/A
EKU: server
Root certificate: private CA
XMPP Gateway
*Required only for public
IM connectivity with AIM
Edge Server 1, Edge Server 2
Internal FQDN: intsrv.<ad-domain>
Certificate SN: intsrv.<ad-domain>
Certificate SAN:
EKU: server
Root certificate: private CA
Access FQDN: accesssrv.<sip-domain>
Certificate SN: accesssrv.<sip-domain>
Certificate SAN: accesssrv.<sip-domain>,
sip.<sip-domain>
EKU: server, client*
Root certificate: public CA
Conference FQDN: N/A
Certificate SN: conf.<sip-domain>
Certificate SAN: N/A
EKU: server
Root certificate: public CA
A/V FQDN: av.<sip-domain>
Certificate SN: av.<sip-domain>
Certificate SAN: N/A
EKU: server
Root certificate: private CA
Edge Servers
Group Chat Server
FQDN: chatsrv.<ad-domain>
Certificate SN: chatsrv.<ad-domain>
Certificate SAN: N/A
EKU: server, client
Root certificate: private CA
Monitoring Server
FQDN: monsrv.<ad-domain>
Certificate SN: monsrv.<ad-domain>
Certificate SAN: N/A
EKU: server
Root certificate: private CA
Communicator Web Access Server
FQDN: cwasrv.<ad-domain>
Certificate SN: cwasrv.<ad-domain>
Certificate SAN: cwasrv.<ad-domain>, cwa.<sip-domain>, as.cwa.<sip-domain>,
download.cwa.<sip-domain>
EKU: server
Root certificate: private CA
FQDN: xmpp.<sip-domain> (2)
Certificate SN: xmpp.<sip-domain>
Certificate SAN: N/A
EKU: server
Root certificate: public CA
(1)
This FQDN is for connectivity
to internal Edge Servers
(2)
This FQDN is for connectivity
to external XMPP gateways
MRAS traffic
HTTPS:443
SIP/TLS:5061
MSMQ
SIP/MTLS:5062
Monitoring
Server
Web Conf Edge - PSOM/TLS:443
Access Edge - SIP/TLS:443
This media traffic goes
directly to the A/V Edge. The
A/V Edge must have publicly
routable IP addresses
If using a single Edge
Server, the public Edge IP
addresses can be NAT-ed
by your external firewall.
2 inbound and 2 outbound
unidirectional streams
STUN/TCP:443, STUN/UDP:3478
SIP/MTLS:5061
STUN/TCP:443,STUN/UDP:3478
· Publish SRV record for _sipfederationtls._tcp.<sip-domain>, which resolves to the Access Edge FQDN, accesssrv.<sip-
domain>.
· Publish SRV record for _sip._tls.<sip-domain>, which resolves to the Access Edge FQDN. This is required for federated and
anonymous connections to Live Meetings.
· Publish SRV record for _xmpp-server._tcp.<sip-domain>, which resolves to the gateway NIC of the XMPP gateway.
·
· Publish A record for Access Edge FQDN, accesssrv.<sip-domain>, which resolves to the Access Edge public IP address.
· Publish A record for A/V Edge FQDN, av.<sip-domain>, which resolves to the A/V Edge public IP address.
· Publish A record for Conferencing Edge FQDN, conf.<sip-domain>, which resolves to the Conferencing Edge public IP address.
· Publish A record for Communicator Web Access to the reverse proxy FQDN, which resolves to public IP address of reverse
proxy
DNS Configuration
Firewall Configuration
Ports to open on internal firewall:
accesssrv.<sip-domain>: TCP 5061, TCP 5062, TCP 5063, TCP
5064, TCP 5071, TCP 5072, TCP 5073, TCP 5074
conf.<sip-domain>: TCP 8057
av.<sip-domain>: TCP 443, UDP 3478, TCP 50,000-59,999
SIP/MTLS
SIP/MTLS
Reference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspx
Reference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspxReference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspx
Reference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspx
http://technet.microsoft.com/en-us/library/dd425257(office.13).aspx
SIP/MTLS
Ports to open on external firewall:
accesssrv.<sip-domain>: TCP 443, TCP 5061
conf.<sip-domain>: TCP 443
av.<sip-domain>: TCP 443, UDP 3478, TCP 50,000-59,999
xmpp.<sip-domain>: TCP 5269
Direction of arrow indicates which
server initiates the connection.
Subsequent traffic is bi-directional.
Communicator
Web Access
Server
Author: Rui Maximo — Designer: Ken Circeo
Reviewers: Rick Kingslan, Benoit Boudeville, Paul Brombley, Nick Smith, Brandon Taylor, Stefan Plizga, Greg Anthony
SIP/TCP:5060,5061
This media traffic goes
directly to the A/V Edge. The
A/V Edge must have publicly
routable IP addresses
If using a single Edge
Server, the public Edge IP
addresses can be NAT-ed
by your external firewall.
RDP/SRTP/TCP:1024-65535
Peer-to-peer application
sharing session
Kerberos used for user authentication
LDAP used to access Active Directory
SIP/TLS:5061
PSOM/MTLS:8057
STUN/TCP:443, STUN/UDP:3478
Directors
Monitoring
Server
SIP/MTLS
SIP/MTLS:5061
MSMQ
SIP/MTLS:5061
SIP/MTLS:5061
Directors
Codec varies on workload:
- SIREN for audio
- RTVideo for video
Edge
Servers
Directors
SIP/TLS:5061
SIP/MTLS:5062
SIP/TLS:5061
Monitoring
Server
Exchange
UM Server
Port number to service traffic assignment:
5062 - Media Relay Authentication Service
5064 - Telephony Conferencing Service
5069 - Monitoring (QoE) Agent
5071 - Response Group Service
5072 - Conferencing Attendant Service
5073 - Conferencing Announcement Service
5074 - Outside Voice Control Service
MSMQ
MRAS traffic
Port number to service traffic assignment:
5062 - Media Relay Authentication Service
5065 - Application Sharing Conferencing Service
5069 - Monitoring (QoE) Agent
SIP/TLS:5061
SIP/MTLS:5062
SIP/MTLS:5061
Port number to service traffic assignment:
5063 - A/V Conferencing Service
5069 - Monitoring (QoE) Agent
MSMQ
Port number to service traffic assignment:
5062 - IM Conferencing Service
5069 - Monitoring (QoE) Agent
MSMQ
Monitoring
Server
Archiving
Server
Kerberos:88, LDAP:389
Internal user sign-in process:
1. Client resolves DNS SRV record _sipinternaltls._tcp.<sip-domain> to Director.
2. Client connects to Director.
3. Director redirects client to user’s home pool.
(2)
HTTPS:443
RDP/SRTP:49152-65535
RDP/SRTP/TCP:49152-65535
Group Chat
Server
Reverse proxy
MRAS traffic
SIP/MTLS:5061
Communicator
For Mac

More Related Content

What's hot

us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...sonjeku1
 
Introduction to SIP(Session Initiation Protocol)
Introduction to SIP(Session Initiation Protocol)Introduction to SIP(Session Initiation Protocol)
Introduction to SIP(Session Initiation Protocol)William Lee
 
(NET404) Making Every Packet Count
(NET404) Making Every Packet Count(NET404) Making Every Packet Count
(NET404) Making Every Packet CountAmazon Web Services
 
Curso: Redes y telecomunicaciones: 07 Protoclos TCP/IP
Curso: Redes y telecomunicaciones: 07 Protoclos TCP/IPCurso: Redes y telecomunicaciones: 07 Protoclos TCP/IP
Curso: Redes y telecomunicaciones: 07 Protoclos TCP/IPJack Daniel Cáceres Meza
 
Troubleshooting Firewalls (2012 San Diego)
Troubleshooting Firewalls (2012 San Diego)Troubleshooting Firewalls (2012 San Diego)
Troubleshooting Firewalls (2012 San Diego)Cisco Security
 
05 module managing your network enviornment
05  module managing your network enviornment05  module managing your network enviornment
05 module managing your network enviornmentAsif
 
Nessus scan report using the defualt scan policy - Tareq Hanaysha
Nessus scan report using the defualt scan policy - Tareq HanayshaNessus scan report using the defualt scan policy - Tareq Hanaysha
Nessus scan report using the defualt scan policy - Tareq HanayshaHanaysha
 
How to Use GSM/3G/4G in Embedded Linux Systems
How to Use GSM/3G/4G in Embedded Linux SystemsHow to Use GSM/3G/4G in Embedded Linux Systems
How to Use GSM/3G/4G in Embedded Linux SystemsToradex
 
Converged office engineering detail
Converged office engineering detailConverged office engineering detail
Converged office engineering detailGeorge Vlismas
 
Tonyfortunatoiperfquickstart 1212633021928769-8
Tonyfortunatoiperfquickstart 1212633021928769-8Tonyfortunatoiperfquickstart 1212633021928769-8
Tonyfortunatoiperfquickstart 1212633021928769-8Jamil Jamil
 
DPDK & Layer 4 Packet Processing
DPDK & Layer 4 Packet ProcessingDPDK & Layer 4 Packet Processing
DPDK & Layer 4 Packet ProcessingMichelle Holley
 
Cellular technology with Embedded Linux - COSCUP 2016
Cellular technology with Embedded Linux - COSCUP 2016Cellular technology with Embedded Linux - COSCUP 2016
Cellular technology with Embedded Linux - COSCUP 2016SZ Lin
 
Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013
Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013
Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013Fatma Ceylan
 
introduction to security
introduction to securityintroduction to security
introduction to securityahmad amiruddin
 
LA Micro Stock Report 30th October 2013
LA Micro Stock Report 30th October 2013LA Micro Stock Report 30th October 2013
LA Micro Stock Report 30th October 2013LA Micro Group UK Ltd
 
Ccna 4 Chapter 3 V4.0 Answers
Ccna 4 Chapter 3 V4.0 AnswersCcna 4 Chapter 3 V4.0 Answers
Ccna 4 Chapter 3 V4.0 Answersccna4discovery
 
Ak13 upgrade
Ak13 upgradeAk13 upgrade
Ak13 upgradeAccenture
 

What's hot (20)

us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-La...
 
Introduction to SIP(Session Initiation Protocol)
Introduction to SIP(Session Initiation Protocol)Introduction to SIP(Session Initiation Protocol)
Introduction to SIP(Session Initiation Protocol)
 
(NET404) Making Every Packet Count
(NET404) Making Every Packet Count(NET404) Making Every Packet Count
(NET404) Making Every Packet Count
 
Curso: Redes y telecomunicaciones: 07 Protoclos TCP/IP
Curso: Redes y telecomunicaciones: 07 Protoclos TCP/IPCurso: Redes y telecomunicaciones: 07 Protoclos TCP/IP
Curso: Redes y telecomunicaciones: 07 Protoclos TCP/IP
 
Troubleshooting Firewalls (2012 San Diego)
Troubleshooting Firewalls (2012 San Diego)Troubleshooting Firewalls (2012 San Diego)
Troubleshooting Firewalls (2012 San Diego)
 
05 module managing your network enviornment
05  module managing your network enviornment05  module managing your network enviornment
05 module managing your network enviornment
 
TekIVR Manual
TekIVR ManualTekIVR Manual
TekIVR Manual
 
Client server
Client serverClient server
Client server
 
Nessus scan report using the defualt scan policy - Tareq Hanaysha
Nessus scan report using the defualt scan policy - Tareq HanayshaNessus scan report using the defualt scan policy - Tareq Hanaysha
Nessus scan report using the defualt scan policy - Tareq Hanaysha
 
How to Use GSM/3G/4G in Embedded Linux Systems
How to Use GSM/3G/4G in Embedded Linux SystemsHow to Use GSM/3G/4G in Embedded Linux Systems
How to Use GSM/3G/4G in Embedded Linux Systems
 
IPv6 DHCP
IPv6 DHCPIPv6 DHCP
IPv6 DHCP
 
Converged office engineering detail
Converged office engineering detailConverged office engineering detail
Converged office engineering detail
 
Tonyfortunatoiperfquickstart 1212633021928769-8
Tonyfortunatoiperfquickstart 1212633021928769-8Tonyfortunatoiperfquickstart 1212633021928769-8
Tonyfortunatoiperfquickstart 1212633021928769-8
 
DPDK & Layer 4 Packet Processing
DPDK & Layer 4 Packet ProcessingDPDK & Layer 4 Packet Processing
DPDK & Layer 4 Packet Processing
 
Cellular technology with Embedded Linux - COSCUP 2016
Cellular technology with Embedded Linux - COSCUP 2016Cellular technology with Embedded Linux - COSCUP 2016
Cellular technology with Embedded Linux - COSCUP 2016
 
Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013
Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013
Dw1601 dw1702 dw1703_dw1705_and_dw1901_release_notes_rc_win7_combo_07_15_2013
 
introduction to security
introduction to securityintroduction to security
introduction to security
 
LA Micro Stock Report 30th October 2013
LA Micro Stock Report 30th October 2013LA Micro Stock Report 30th October 2013
LA Micro Stock Report 30th October 2013
 
Ccna 4 Chapter 3 V4.0 Answers
Ccna 4 Chapter 3 V4.0 AnswersCcna 4 Chapter 3 V4.0 Answers
Ccna 4 Chapter 3 V4.0 Answers
 
Ak13 upgrade
Ak13 upgradeAk13 upgrade
Ak13 upgrade
 

Similar to Office Comunnications Server 2007 R2 Poster

vCenter and ESXi network port communications
vCenter and ESXi network port communicationsvCenter and ESXi network port communications
vCenter and ESXi network port communicationsAnimesh Dixit
 
DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...
DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...
DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...David Pasek
 
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.Louis Göhl
 
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...CODE BLUE
 
Simple hybrid voice deployments with Sonus
Simple hybrid voice deployments with SonusSimple hybrid voice deployments with Sonus
Simple hybrid voice deployments with Sonusmscug
 
Simple hybrid voice deployments with Sonus
Simple hybrid voice deployments with SonusSimple hybrid voice deployments with Sonus
Simple hybrid voice deployments with SonusAdam Hand
 
Fast Streaming into Clickhouse with Apache Pulsar
Fast Streaming into Clickhouse with Apache PulsarFast Streaming into Clickhouse with Apache Pulsar
Fast Streaming into Clickhouse with Apache PulsarTimothy Spann
 
Data Center Design Guide 4 2
Data Center Design Guide 4 2Data Center Design Guide 4 2
Data Center Design Guide 4 2Fiyaz Syed
 
Рабочие нагрузки Skype for business 2015 UC Lab
Рабочие нагрузки Skype for business 2015 UC LabРабочие нагрузки Skype for business 2015 UC Lab
Рабочие нагрузки Skype for business 2015 UC LabUC2
 
(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014
(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014
(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014Amazon Web Services
 
Authenticated Identites in VoIP Call Control
Authenticated Identites in VoIP Call ControlAuthenticated Identites in VoIP Call Control
Authenticated Identites in VoIP Call ControlWarren Bent
 
Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2Warren Bent
 
Hunting for APT in network logs workshop presentation
Hunting for APT in network logs workshop presentationHunting for APT in network logs workshop presentation
Hunting for APT in network logs workshop presentationOlehLevytskyi1
 
Monitoring CloudStack and components
Monitoring CloudStack and componentsMonitoring CloudStack and components
Monitoring CloudStack and componentsShapeBlue
 
Big datadc skyfall_preso_v2
Big datadc skyfall_preso_v2Big datadc skyfall_preso_v2
Big datadc skyfall_preso_v2abramsm
 
Innovation in SDN Tools and Platforms
Innovation in SDN Tools and PlatformsInnovation in SDN Tools and Platforms
Innovation in SDN Tools and PlatformsUmesh Krishnaswamy
 
Practical steps to mitigate DDoS attacks
Practical steps to mitigate DDoS attacksPractical steps to mitigate DDoS attacks
Practical steps to mitigate DDoS attacksMartin Holovský
 
Taylor & sons financial
Taylor & sons financialTaylor & sons financial
Taylor & sons financialTezie28
 

Similar to Office Comunnications Server 2007 R2 Poster (20)

vCenter and ESXi network port communications
vCenter and ESXi network port communicationsvCenter and ESXi network port communications
vCenter and ESXi network port communications
 
DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...
DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...
DELL (OME) Open Manage Esentials network connections (TCP/UDP ports) and fire...
 
Bezpečnostní architektura F5
Bezpečnostní architektura F5Bezpečnostní architektura F5
Bezpečnostní architektura F5
 
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
SVR402: DirectAccess Technical Drilldown, Part 2 of 2: Putting it all together.
 
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...
A New Era of SSRF - Exploiting URL Parser in Trending Programming Languages! ...
 
Simple hybrid voice deployments with Sonus
Simple hybrid voice deployments with SonusSimple hybrid voice deployments with Sonus
Simple hybrid voice deployments with Sonus
 
Simple hybrid voice deployments with Sonus
Simple hybrid voice deployments with SonusSimple hybrid voice deployments with Sonus
Simple hybrid voice deployments with Sonus
 
Fast Streaming into Clickhouse with Apache Pulsar
Fast Streaming into Clickhouse with Apache PulsarFast Streaming into Clickhouse with Apache Pulsar
Fast Streaming into Clickhouse with Apache Pulsar
 
Data Center Design Guide 4 2
Data Center Design Guide 4 2Data Center Design Guide 4 2
Data Center Design Guide 4 2
 
Рабочие нагрузки Skype for business 2015 UC Lab
Рабочие нагрузки Skype for business 2015 UC LabРабочие нагрузки Skype for business 2015 UC Lab
Рабочие нагрузки Skype for business 2015 UC Lab
 
(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014
(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014
(ARC204) Architecting Microsoft Workloads on AWS | AWS re:Invent 2014
 
Authenticated Identites in VoIP Call Control
Authenticated Identites in VoIP Call ControlAuthenticated Identites in VoIP Call Control
Authenticated Identites in VoIP Call Control
 
Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2Presentation To Vo Ip Round Table V2
Presentation To Vo Ip Round Table V2
 
R bernardino hand_in_assignment_week_1
R bernardino hand_in_assignment_week_1R bernardino hand_in_assignment_week_1
R bernardino hand_in_assignment_week_1
 
Hunting for APT in network logs workshop presentation
Hunting for APT in network logs workshop presentationHunting for APT in network logs workshop presentation
Hunting for APT in network logs workshop presentation
 
Monitoring CloudStack and components
Monitoring CloudStack and componentsMonitoring CloudStack and components
Monitoring CloudStack and components
 
Big datadc skyfall_preso_v2
Big datadc skyfall_preso_v2Big datadc skyfall_preso_v2
Big datadc skyfall_preso_v2
 
Innovation in SDN Tools and Platforms
Innovation in SDN Tools and PlatformsInnovation in SDN Tools and Platforms
Innovation in SDN Tools and Platforms
 
Practical steps to mitigate DDoS attacks
Practical steps to mitigate DDoS attacksPractical steps to mitigate DDoS attacks
Practical steps to mitigate DDoS attacks
 
Taylor & sons financial
Taylor & sons financialTaylor & sons financial
Taylor & sons financial
 

More from Paulo Freitas

VMWARE Professionals - Foundation Hybrid Clouds and Costs
VMWARE Professionals -  Foundation Hybrid Clouds and CostsVMWARE Professionals -  Foundation Hybrid Clouds and Costs
VMWARE Professionals - Foundation Hybrid Clouds and CostsPaulo Freitas
 
VMWARE Professionals - Cross-Plattform Mangement
VMWARE Professionals -  Cross-Plattform MangementVMWARE Professionals -  Cross-Plattform Mangement
VMWARE Professionals - Cross-Plattform MangementPaulo Freitas
 
VMWARE Professionals - App Management
VMWARE Professionals - App ManagementVMWARE Professionals - App Management
VMWARE Professionals - App ManagementPaulo Freitas
 
VMWARE Professionals - Intro to System Center 2012 SP1
VMWARE Professionals -  Intro to System Center 2012 SP1VMWARE Professionals -  Intro to System Center 2012 SP1
VMWARE Professionals - Intro to System Center 2012 SP1Paulo Freitas
 
VMWARE Professionals - Availability and Resiliency
VMWARE Professionals -  Availability and ResiliencyVMWARE Professionals -  Availability and Resiliency
VMWARE Professionals - Availability and ResiliencyPaulo Freitas
 
VMWARE Professionals - Security, Multitenancy and Flexibility
VMWARE Professionals -  Security, Multitenancy and FlexibilityVMWARE Professionals -  Security, Multitenancy and Flexibility
VMWARE Professionals - Security, Multitenancy and FlexibilityPaulo Freitas
 
VMWARE Professionals - Storage and Resources
VMWARE Professionals -  Storage and ResourcesVMWARE Professionals -  Storage and Resources
VMWARE Professionals - Storage and ResourcesPaulo Freitas
 
VMWARE Professionals - Intro and Scale
VMWARE Professionals -  Intro and ScaleVMWARE Professionals -  Intro and Scale
VMWARE Professionals - Intro and ScalePaulo Freitas
 
Hyper-V Integration with other System Center 2012 Components
Hyper-V Integration with other System Center 2012 ComponentsHyper-V Integration with other System Center 2012 Components
Hyper-V Integration with other System Center 2012 ComponentsPaulo Freitas
 
Hyper-V Integration with System Center 2012 Virtual Machine Manager
Hyper-V Integration with System Center 2012 Virtual Machine ManagerHyper-V Integration with System Center 2012 Virtual Machine Manager
Hyper-V Integration with System Center 2012 Virtual Machine ManagerPaulo Freitas
 
Hyper-V High Availability and Live Migration
Hyper-V High Availability and Live MigrationHyper-V High Availability and Live Migration
Hyper-V High Availability and Live MigrationPaulo Freitas
 
Hyper-V Infrastructure
Hyper-V InfrastructureHyper-V Infrastructure
Hyper-V InfrastructurePaulo Freitas
 
Windows Server 2012 R2 Jump Start - WEB
Windows Server 2012 R2 Jump Start - WEBWindows Server 2012 R2 Jump Start - WEB
Windows Server 2012 R2 Jump Start - WEBPaulo Freitas
 
Windows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIPWindows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIPPaulo Freitas
 
Windows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - IntroWindows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - IntroPaulo Freitas
 
Windows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - IntroWindows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - IntroPaulo Freitas
 
Multi site Clustering with Windows Server 2008 Enterprise
Multi site Clustering with Windows Server 2008 EnterpriseMulti site Clustering with Windows Server 2008 Enterprise
Multi site Clustering with Windows Server 2008 EnterprisePaulo Freitas
 

More from Paulo Freitas (20)

VMWARE Professionals - Foundation Hybrid Clouds and Costs
VMWARE Professionals -  Foundation Hybrid Clouds and CostsVMWARE Professionals -  Foundation Hybrid Clouds and Costs
VMWARE Professionals - Foundation Hybrid Clouds and Costs
 
VMWARE Professionals - Cross-Plattform Mangement
VMWARE Professionals -  Cross-Plattform MangementVMWARE Professionals -  Cross-Plattform Mangement
VMWARE Professionals - Cross-Plattform Mangement
 
VMWARE Professionals - App Management
VMWARE Professionals - App ManagementVMWARE Professionals - App Management
VMWARE Professionals - App Management
 
VMWARE Professionals - Intro to System Center 2012 SP1
VMWARE Professionals -  Intro to System Center 2012 SP1VMWARE Professionals -  Intro to System Center 2012 SP1
VMWARE Professionals - Intro to System Center 2012 SP1
 
VMWARE Professionals - Availability and Resiliency
VMWARE Professionals -  Availability and ResiliencyVMWARE Professionals -  Availability and Resiliency
VMWARE Professionals - Availability and Resiliency
 
VMWARE Professionals - Security, Multitenancy and Flexibility
VMWARE Professionals -  Security, Multitenancy and FlexibilityVMWARE Professionals -  Security, Multitenancy and Flexibility
VMWARE Professionals - Security, Multitenancy and Flexibility
 
VMWARE Professionals - Storage and Resources
VMWARE Professionals -  Storage and ResourcesVMWARE Professionals -  Storage and Resources
VMWARE Professionals - Storage and Resources
 
VMWARE Professionals - Intro and Scale
VMWARE Professionals -  Intro and ScaleVMWARE Professionals -  Intro and Scale
VMWARE Professionals - Intro and Scale
 
Hyper-V Integration with other System Center 2012 Components
Hyper-V Integration with other System Center 2012 ComponentsHyper-V Integration with other System Center 2012 Components
Hyper-V Integration with other System Center 2012 Components
 
Hyper-V Integration with System Center 2012 Virtual Machine Manager
Hyper-V Integration with System Center 2012 Virtual Machine ManagerHyper-V Integration with System Center 2012 Virtual Machine Manager
Hyper-V Integration with System Center 2012 Virtual Machine Manager
 
Hyper-V High Availability and Live Migration
Hyper-V High Availability and Live MigrationHyper-V High Availability and Live Migration
Hyper-V High Availability and Live Migration
 
Hyper-V Management
Hyper-V ManagementHyper-V Management
Hyper-V Management
 
Hyper-V Storage
Hyper-V StorageHyper-V Storage
Hyper-V Storage
 
Hyper-V Networking
Hyper-V NetworkingHyper-V Networking
Hyper-V Networking
 
Hyper-V Infrastructure
Hyper-V InfrastructureHyper-V Infrastructure
Hyper-V Infrastructure
 
Windows Server 2012 R2 Jump Start - WEB
Windows Server 2012 R2 Jump Start - WEBWindows Server 2012 R2 Jump Start - WEB
Windows Server 2012 R2 Jump Start - WEB
 
Windows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIPWindows Server 2012 R2 Jump Start - AIP
Windows Server 2012 R2 Jump Start - AIP
 
Windows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - IntroWindows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - Intro
 
Windows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - IntroWindows Server 2012 R2 Jump Start - Intro
Windows Server 2012 R2 Jump Start - Intro
 
Multi site Clustering with Windows Server 2008 Enterprise
Multi site Clustering with Windows Server 2008 EnterpriseMulti site Clustering with Windows Server 2008 Enterprise
Multi site Clustering with Windows Server 2008 Enterprise
 

Recently uploaded

Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityWSO2
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfOrbitshub
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Zilliz
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 

Recently uploaded (20)

Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 

Office Comunnications Server 2007 R2 Poster

  • 1. LEGEND Enterprise poolHardware load balancer Edge Servers Front End Servers SQL back-end server Directors Communicator Web Access Server Archiving Server Monitoring Server Group Chat Server Update Server Exchange UM Server Mediation Server XMPP gatewayReverse proxy © 2009 Microsoft Corporation. Active Directory, Office, MSN, and any associated logos are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. All rights reserved. Other trademarks or trade names mentioned herein are the property of their respective owners. Workload Architecture http://twitter.com/DrRezhttp://TechNet.microsoft.com/office/OCS http://go.microsoft.com/fwlink/?LinkId=181907 Multi-NIC support CERTIFICATE REQUIREMENTS Communicator Phone Edition Office Live MeetingOffice Communicator Attendant Console Communicator Web Access CLIENTS SIP/TLS:443 Edge Servers External Firewall Internal Firewall Directors XMPP Gateway Edge Servers External firewall Internal firewall RTP/SRTP traffic IM and Presence Workload A/V and Web Conferencing Workload Enterprise Voice Workload HTTPS:443 C3P/HTTPS:444 SIP/MTLS:5061 Application Sharing Workload XMPP/TCP:5269 Pools Connectivity to: • IP-PSTN gateway • IP/PBX • Direct SIP • SIP trunk Pools Reverse proxy Access Edge - SIP/MTLS:5061Federated Company Yahoo! MSN AOL Jabber Gmail HTTPS:443 A/V Edge - STUN/TCP:443, STUN/UDP:3478 Access Edge - SIP/TLS:443 A/V Edge – SRTP:443,3478,50,000-59,999 SIP/MTLS:5061 HTTPS:443 Access Edge - SIP/TLS:443 SIP/MTLS:5061 HTTPS:443 SRTP/RTCP:60,000-64,000 SIP/TLS:5061 SIP traffic External firewall Internal firewall HTTPS:443 Communicator Web Access Server HTTPS:443 Pools A/V Edge – SRTP:443,3478,50,000-59,999 HTTPS:443 SRTP/RTCP:60,000-64,000 Access Edge - SIP/TLS:443 SIP/MTLS:5061 Edge Servers External firewall Internal firewall HTTPS:443 Reverse proxy HTTPS traffic HTTPS:443 Pools HTTPS:443 SIP traffic: signaling SIP/MTLS:5061 SIP/TLS:5061 RTP/SRTP traffic: A/V Conferencing A/V Edge - STUN/TCP:443, STUN/UDP:3478 A/V Edge – SRTP:443,3478,50,000-59,999 SRTP/UDP:49152-65535 This media traffic goes directly to the A/V Edge. The A/V Edge must have publicly routable IP addresses If using a single Edge Server, the public Edge IP addresses can be NAT-ed by your external firewall. Range of ports is configurable RDP/SRTP traffic HTTPS traffic SIP traffic SIP traffic: signaling and IM XMPP traffic HTTPS traffic MSMQ traffic SIP/MTLS:5062 PSOM traffic: Web Conferencing HTTPS:443 is used to download address book and updates Communicator Mobile Group Chat Group Chat file share Address book file share Group Chat Compliance Server Meeting content + metadata + compliance file share PSOM/TLS:8057 HTTPS:443 HTTPS:443 HTTPS:443 is used to download conferencing content + metadata Media codec varies on workload: - RTAudio - G.711 Traffic goes directly to Web Conferencing Service WITHOUT going through the pool’s hardware load balancer 2 inbound and 2 outbound unidirectional streams. Media codec varies on workload: - RTAudio for audio - RTVideo for video Range of ports is configurable SRTP consists of two unidirectional streams. RTCP traffic piggy backs on the SRTP stream. Media codec varies on workload: - RTAudio - G.711 SIP/TLS:5061 SRVquery (1) (3) Range of ports is configurable Traffic goes directly to A/V Conferencing Service WITHOUT going through the pool’s hardware load balancer Mediation Server FQDN: medsrv.<ad-domain> Certificate SN: medsrv.<ad-domain> Certificate SAN: N/A EKU: server Root certificate: private CA Exchange UM Server FQDN: umsrv.<ad-domain> Certificate SN: umsrv.<ad-domain> Certificate SAN: N/A EKU: server Root certificate: private CA Directors Front End Server 1, Front End Server 2 FQDN: pool.<ad-domain> Certificate SN: pool.<ad-domain> Certificate SAN: pool.<ad-domain>, EKU: server Root certificate: private CA Pool Director 1, Director 2 FQDN: dir.<ad-domain> Certificate SN: dir.<ad-domain> Certificate SAN: dir.<ad-domain>, sipinternal.<sip-domain> EKU: server Root certificate: private CA STUN/TCP:443, STUN/UDP:3478 Mediation Server External user sign-in process: 1. Client resolves DNS SRV record _sip._tls.<sip-domain> to Edge Server. 2. Client connects to Edge Server. 3. Edge Server proxies connection to Director. 4. Director authenticates user and proxies connection to user’s home pool. FQDN: xmppsrv.<sip-domain> (1) Certificate SN: xmppsrv.<sip-domain> Certificate SAN: N/A EKU: server Root certificate: private CA XMPP Gateway *Required only for public IM connectivity with AIM Edge Server 1, Edge Server 2 Internal FQDN: intsrv.<ad-domain> Certificate SN: intsrv.<ad-domain> Certificate SAN: EKU: server Root certificate: private CA Access FQDN: accesssrv.<sip-domain> Certificate SN: accesssrv.<sip-domain> Certificate SAN: accesssrv.<sip-domain>, sip.<sip-domain> EKU: server, client* Root certificate: public CA Conference FQDN: N/A Certificate SN: conf.<sip-domain> Certificate SAN: N/A EKU: server Root certificate: public CA A/V FQDN: av.<sip-domain> Certificate SN: av.<sip-domain> Certificate SAN: N/A EKU: server Root certificate: private CA Edge Servers Group Chat Server FQDN: chatsrv.<ad-domain> Certificate SN: chatsrv.<ad-domain> Certificate SAN: N/A EKU: server, client Root certificate: private CA Monitoring Server FQDN: monsrv.<ad-domain> Certificate SN: monsrv.<ad-domain> Certificate SAN: N/A EKU: server Root certificate: private CA Communicator Web Access Server FQDN: cwasrv.<ad-domain> Certificate SN: cwasrv.<ad-domain> Certificate SAN: cwasrv.<ad-domain>, cwa.<sip-domain>, as.cwa.<sip-domain>, download.cwa.<sip-domain> EKU: server Root certificate: private CA FQDN: xmpp.<sip-domain> (2) Certificate SN: xmpp.<sip-domain> Certificate SAN: N/A EKU: server Root certificate: public CA (1) This FQDN is for connectivity to internal Edge Servers (2) This FQDN is for connectivity to external XMPP gateways MRAS traffic HTTPS:443 SIP/TLS:5061 MSMQ SIP/MTLS:5062 Monitoring Server Web Conf Edge - PSOM/TLS:443 Access Edge - SIP/TLS:443 This media traffic goes directly to the A/V Edge. The A/V Edge must have publicly routable IP addresses If using a single Edge Server, the public Edge IP addresses can be NAT-ed by your external firewall. 2 inbound and 2 outbound unidirectional streams STUN/TCP:443, STUN/UDP:3478 SIP/MTLS:5061 STUN/TCP:443,STUN/UDP:3478 · Publish SRV record for _sipfederationtls._tcp.<sip-domain>, which resolves to the Access Edge FQDN, accesssrv.<sip- domain>. · Publish SRV record for _sip._tls.<sip-domain>, which resolves to the Access Edge FQDN. This is required for federated and anonymous connections to Live Meetings. · Publish SRV record for _xmpp-server._tcp.<sip-domain>, which resolves to the gateway NIC of the XMPP gateway. · · Publish A record for Access Edge FQDN, accesssrv.<sip-domain>, which resolves to the Access Edge public IP address. · Publish A record for A/V Edge FQDN, av.<sip-domain>, which resolves to the A/V Edge public IP address. · Publish A record for Conferencing Edge FQDN, conf.<sip-domain>, which resolves to the Conferencing Edge public IP address. · Publish A record for Communicator Web Access to the reverse proxy FQDN, which resolves to public IP address of reverse proxy DNS Configuration Firewall Configuration Ports to open on internal firewall: accesssrv.<sip-domain>: TCP 5061, TCP 5062, TCP 5063, TCP 5064, TCP 5071, TCP 5072, TCP 5073, TCP 5074 conf.<sip-domain>: TCP 8057 av.<sip-domain>: TCP 443, UDP 3478, TCP 50,000-59,999 SIP/MTLS SIP/MTLS Reference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspx Reference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspxReference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspx Reference: http://technet.microsoft.com/en-us/library/dd425238(office.13).aspx http://technet.microsoft.com/en-us/library/dd425257(office.13).aspx SIP/MTLS Ports to open on external firewall: accesssrv.<sip-domain>: TCP 443, TCP 5061 conf.<sip-domain>: TCP 443 av.<sip-domain>: TCP 443, UDP 3478, TCP 50,000-59,999 xmpp.<sip-domain>: TCP 5269 Direction of arrow indicates which server initiates the connection. Subsequent traffic is bi-directional. Communicator Web Access Server Author: Rui Maximo — Designer: Ken Circeo Reviewers: Rick Kingslan, Benoit Boudeville, Paul Brombley, Nick Smith, Brandon Taylor, Stefan Plizga, Greg Anthony SIP/TCP:5060,5061 This media traffic goes directly to the A/V Edge. The A/V Edge must have publicly routable IP addresses If using a single Edge Server, the public Edge IP addresses can be NAT-ed by your external firewall. RDP/SRTP/TCP:1024-65535 Peer-to-peer application sharing session Kerberos used for user authentication LDAP used to access Active Directory SIP/TLS:5061 PSOM/MTLS:8057 STUN/TCP:443, STUN/UDP:3478 Directors Monitoring Server SIP/MTLS SIP/MTLS:5061 MSMQ SIP/MTLS:5061 SIP/MTLS:5061 Directors Codec varies on workload: - SIREN for audio - RTVideo for video Edge Servers Directors SIP/TLS:5061 SIP/MTLS:5062 SIP/TLS:5061 Monitoring Server Exchange UM Server Port number to service traffic assignment: 5062 - Media Relay Authentication Service 5064 - Telephony Conferencing Service 5069 - Monitoring (QoE) Agent 5071 - Response Group Service 5072 - Conferencing Attendant Service 5073 - Conferencing Announcement Service 5074 - Outside Voice Control Service MSMQ MRAS traffic Port number to service traffic assignment: 5062 - Media Relay Authentication Service 5065 - Application Sharing Conferencing Service 5069 - Monitoring (QoE) Agent SIP/TLS:5061 SIP/MTLS:5062 SIP/MTLS:5061 Port number to service traffic assignment: 5063 - A/V Conferencing Service 5069 - Monitoring (QoE) Agent MSMQ Port number to service traffic assignment: 5062 - IM Conferencing Service 5069 - Monitoring (QoE) Agent MSMQ Monitoring Server Archiving Server Kerberos:88, LDAP:389 Internal user sign-in process: 1. Client resolves DNS SRV record _sipinternaltls._tcp.<sip-domain> to Director. 2. Client connects to Director. 3. Director redirects client to user’s home pool. (2) HTTPS:443 RDP/SRTP:49152-65535 RDP/SRTP/TCP:49152-65535 Group Chat Server Reverse proxy MRAS traffic SIP/MTLS:5061 Communicator For Mac