<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>A/V Edge and Publicly routable IP addresses (Part ii)</title><link>http://blogs.technet.com/chlacy/archive/2008/03/12/a-v-edge-and-publicly-routable-ip-addresses-part-ii.aspx</link><description>I happen to be part of an e-mail thread this week with several members of the product group and we were discussing the need for publicly routable IP address on the external interface of the A/V edge server. I wanted to share with you the information that</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: A/V Edge and Publicly routable IP addresses (Part ii)</title><link>http://blogs.technet.com/chlacy/archive/2008/03/12/a-v-edge-and-publicly-routable-ip-addresses-part-ii.aspx#2997985</link><pubDate>Fri, 14 Mar 2008 13:37:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2997985</guid><dc:creator>richardo</dc:creator><description>&lt;p&gt;What I am really curious about, is the actual implementation of the &amp;quot;firewall&amp;quot; on the external side of the edge server.&lt;/p&gt;
&lt;p&gt;All the guides just put a simple red line, that represents the border between the edge server and the internet, but they lack to detail what kind of firewalling should be put there.&lt;/p&gt;
&lt;p&gt;If NAT isn't an issue, one would simply put a PC router in DMZ, that will translate packets coming to its public leg into a private IP used by the edge server's external leg and things are fine. However, if we should use public IP on the external side, I feel that things get complicated, as the router and even the edge external leg should have its own public IP. In this case if I understand correctly, we have 2 choices:&lt;/p&gt;
&lt;p&gt;-filter the traffic arriving to the edge's external interface using Layer3 switch rules (that means, filtering applyed to the router of the ISP that hosts our DMZ servers)&lt;/p&gt;
&lt;p&gt;-put an additional PC router into the DMZ that will route packets arriving from the ISP via the PC router to the edge's external public IP, and do the filtering meanwhile.&lt;/p&gt;
&lt;p&gt;Filtering may not be possible on the edge server locally, as colocation with ISA is not supported, and the built-in w2k3 firewall is not so flexible to easily create those dynamic bidirectional port-ranges.&lt;/p&gt;</description></item><item><title>Public IP Requirements for A/V Edge</title><link>http://blogs.technet.com/chlacy/archive/2008/03/12/a-v-edge-and-publicly-routable-ip-addresses-part-ii.aspx#3005217</link><pubDate>Sun, 16 Mar 2008 11:56:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3005217</guid><dc:creator>Rob Costello</dc:creator><description>&lt;p&gt;So a few people get nervous when you tell them your going to need a publicly routable IP when implementing&lt;/p&gt;
</description></item><item><title>re: A/V Edge and Publicly routable IP addresses (Part ii)</title><link>http://blogs.technet.com/chlacy/archive/2008/03/12/a-v-edge-and-publicly-routable-ip-addresses-part-ii.aspx#3052986</link><pubDate>Fri, 09 May 2008 17:36:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3052986</guid><dc:creator>Alan Twigg</dc:creator><description>&lt;p&gt;Does anyone have detailed tech info on the STUN\ICE implementation in OCS2007? it doesn't appear to be working correctly in our environment ( we do have a publicly routable ip address and no natting on any firewall )&lt;/p&gt;</description></item></channel></rss>