<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx</link><description>Many organizations utilize Virtual Private Networks (VPNs) to secure traffic when users are outside the corporate network. VPNs have numerous security benefits, but they can actually degrade the call experience for Microsoft Lync users. This occurs because</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3521787</link><pubDate>Fri, 21 Sep 2012 15:38:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3521787</guid><dc:creator>Kevin Peters</dc:creator><description>&lt;p&gt;Hi Austin,&lt;/p&gt;
&lt;p&gt;If you block the traffic on the server side there is still the possibility of Peer to Peer connectivity (from one Lync client to another) over the tunnel. So unless you also block internal client subnets from reaching VPN subnets that wouldn&amp;#39;t resolve the problem for all media flows.&lt;/p&gt;
&lt;p&gt;Hope this helps!&lt;/p&gt;
&lt;p&gt;Kevin&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3521787" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3521494</link><pubDate>Thu, 20 Sep 2012 23:11:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3521494</guid><dc:creator>Austin Bailey</dc:creator><description>&lt;p&gt;Great Article!&lt;/p&gt;
&lt;p&gt;I have one question for you though. If I was to give my VPN users a separate DHCP pool, could I implement the firewall rules on the Lync server side rather than the client side? It would be a gigantic undertaking to modify all of my mobile users windows firewalls to make the suggested change. My thought is to block the VPN IP Subnet on the servers themselves so that the client would be forced to look at the edge for connectivity. Thoughts?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3521494" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3476186</link><pubDate>Thu, 19 Jan 2012 01:23:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3476186</guid><dc:creator>Jason</dc:creator><description>&lt;p&gt;Has anyone that implemented this noticed that the Lync client takes a long time to login when on VPN? &amp;nbsp;Just a nusance, otherwise this solution rocks! &amp;nbsp;Users &amp;quot;Internal&amp;quot; flag is set to fale when on VPN and traffic is routing over the Internet tunnel exclusively - excelelnt article!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3476186" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3475567</link><pubDate>Mon, 16 Jan 2012 10:01:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475567</guid><dc:creator>Mac alvano</dc:creator><description>&lt;p&gt;Nice article, keep it up good work, kevin and randy!&lt;/p&gt;
&lt;p&gt;does link media bypass &amp;lt;a href=&amp;quot;&lt;a rel="nofollow" target="_new" href="http://bestvpnservice.com/providers/22/strong_vpn.html&amp;quot;&amp;gt;strong"&gt;bestvpnservice.com/.../strong_vpn.html&amp;quot;&amp;gt;strong&lt;/a&gt; vpn&amp;lt;/a&amp;gt;?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475567" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3475186</link><pubDate>Thu, 12 Jan 2012 17:48:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475186</guid><dc:creator>Kevin Peters</dc:creator><description>&lt;p&gt;Hi Jason,&lt;/p&gt;
&lt;p&gt;You would want to use a separate DNS server for VPN clients, so public IPs are provided to the VPN users (bypassing the tunnel), but internal IPs are still provided to your internal users. &amp;nbsp;This could not be done from the same DNS server, so you&amp;#39;d need to create at least one, specifically for serving the VPN connections.&lt;/p&gt;
&lt;p&gt;HTH,&lt;/p&gt;
&lt;p&gt;-Kevin&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475186" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3475145</link><pubDate>Thu, 12 Jan 2012 15:51:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475145</guid><dc:creator>Jason</dc:creator><description>&lt;p&gt;Same goes for meet and dialin, I already have these registered on internal DNS using internal IP&amp;#39;s. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475145" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3475143</link><pubDate>Thu, 12 Jan 2012 15:46:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475143</guid><dc:creator>Jason</dc:creator><description>&lt;p&gt;I am confused, I already have an internal DNS entry for &amp;quot;Sip.contoso.com&amp;quot; pointing to an internal address, this suggests resolving it to the edge interface. &amp;nbsp;What will happen to internal users?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475143" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3466223</link><pubDate>Sat, 19 Nov 2011 14:00:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3466223</guid><dc:creator>soder</dc:creator><description>&lt;p&gt;Finally, this has been properly documented. I have to start testing it, and if works, becomes part of my implementation best practices list. Good job!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3466223" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3466205</link><pubDate>Sat, 19 Nov 2011 06:43:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3466205</guid><dc:creator>seo training noida</dc:creator><description>&lt;p&gt;Thank you&lt;/p&gt;
&lt;p&gt;Your blog is very Informative.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3466205" width="1" height="1"&gt;</description></item><item><title>re: Enabling Lync Media to Bypass a VPN Tunnel</title><link>http://blogs.technet.com/b/nexthop/archive/2011/11/15/enabling-lync-media-to-bypass-a-vpn-tunnel.aspx#3466158</link><pubDate>Fri, 18 Nov 2011 19:51:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3466158</guid><dc:creator>Peyton McManus</dc:creator><description>&lt;p&gt;Nice article guys! &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3466158" width="1" height="1"&gt;</description></item></channel></rss>