Information on A/V Edge Ports and Public IP Addresses
I often get asked why the OCS AV Edge server requires a public IP address. The best explanation I've seen was recently posted by Alan Shen over at the OCS Team Blog.
The A/V edge server enables users to participate in audio and video connections from outside the corporate network, such as a point to point call, a conference, leaving a voicemail with Exchange UM, or making a PSTN call. Contoso has deployed the A/V Edge server with two NICs in the perimeter network. The “external” firewall separates the edge server from the internet and the “internal” firewall separates the server from the corporate network. In order for the A/V Edge server to function correctly, the internal firewall must allow traffic to UDP 3478, TCP 443, and TCP 5062 (A/V authentication port). And the external firewall must allow bi-directional traffic to the following ports: UDP 3478, TCP 443, UDP 50,000-59,999, and TCP 50,000-59,999. No NATing behavior is allowed on either firewall. The external IP address must be publically routable and the internal IP address must be routable from within the corporate network.
Read the rest of the article at http://communicationsserverteam.com/archive/2008/03/25/133.aspx
Technorati Tags:
ocs,
edge,
security
Comment Notification
If you would like to receive an email when updates are made to this post, please register here
Subscribe to this post's comments using