TP: 443 HTTP: 80 SIP/TLS: 5061 SIP/TLS: 5061 HTTPS: 443 IM and Presence SIP traffic: signaling and IM XMPP traffic HTTPS traffic MSMQ traffic LS traffic HTTPS: 4443 Director proxies Web traffic to destination pool s Web service. LPE devices also require port 80. ctive Directory ddress book & Persistent hat file share Services and Processes rrow direction indicates which ctual traffic is bi-directional. This port is used to connect to Web Services: download the ddress ook connect to ddress ook Web query URL provide distribution list expansion download meeting content connect to the Mobility Service connect to the utodiscover Service connect to Dial-in URL connect to Lync Web pp connect to ertprovisioningservice user sign-in process: 1. lient discovers Edge Server: a. lyncdiscoverinternal.<sip-domain> b. lyncdiscover.<sip-domain> c. _sipinternaltls._tcp.<sip-domain> d. _sipinternal._tcp.<sip-domain> e. _sip._tls.<sip-domain> f. sipinternal.<sip-domain> g. sip.<sip-domain> h. sipexternal.<sip-domain> 2. lient connects to Edge Server. 3. Edge Server proxies connection to Director. 4. Director authenticates user and proxy connection to user s home pool. user sign-in process: 1. lient discovers Enterprise Pool: a. lyncdiscoverinternal.<sip-domain> b. lyncdiscover.<sip-domain> c. _sipinternaltls._tcp.<sip-domain> d. _sipinternal._tcp.<sip-domain> e. sipinternal.<sip-domain> f. sip.<sip-domain> 2. lient connects to Enterprise Pool server. 3. Enterprise pool server authenticates user and redirects connection to user s home server. ertificate uthority Skype Directory Search ccess Edge SIP/TLS: 443 ccess Edge SIP/MTLS: 5061 federation and Public IM XMPP federation Office 365 XMPP/TP: 5269 SML/HTTPS: 443 DSML/HTTPS: 443 DFS Proxy Publish rule for port 4443 to set forward host header to true. This ensures the original URL is forwarded. SIP/MTLS: 5061 HTTPS: 4443 XMPP/MTLS: 23456 LS/MTLS: 50001-50003 DirSync DFS Single sign-on (SSO) entralized Logging Service Persistent hat ompliance Server Ports to load balance by HL: - 80-8080 - 443-4443 - 5061 [can use DNS load balancing] MSMQ Persistent hat Server ack-end SQL Server 3P/HTTPS: 444 File Share Server SIP/ MTLS: 5041 SIP/MTLS Port number to service traffic assignment: 5062 IM onferencing Service 5086 Mobility Service 5087 Mobility Service 2015 Microsoft orporation. ll rights reserved. To send feedback about this documentation, please write to us at Sfdoc2015@microsoft.com.
TP:5060 TLS:5061 SIP Trunk TLS:5061 SRTP/UDP:49152-65535 PSOM/TLS:8057 /V and Web onferencing Source IP /V Edge /V Edge ny ny D E SIP traffic: signaling HTTP(S) traffic RTP/SRTP traffic: /V onferencing PSOM traffic: Web onferencing IE traffic rrow direction indicates which ctual traffic is bi-directional. Destination IP ny ny /V Edge /V Edge Source Port TP 50,000-59,999 UDP 3478 ny ny odec varies per workload: G.722 for audio H264SV for video odec varies per workload: G.722, Siren or SILK for audio H264SV for video [RTVideo for downlevel clients] odec varies per workload: G.722 for audio H264V for video is used to download conferencing content. Destination Port UDP 3478 UDP 3478 federation If client connects on port 80 during sign-in, it gets redirected to port 443 ccess Edge SIP/TLS:443 ccess Edge Web onf Edge - PSOM/TLS:443 /V Edge STUN/TP:443, UDP:3478 SIP/MTLS/TP:5061 SIP/MTLS/TP:5062 PSOM/MTLS/TP:8057 HTTPS:4443 MRS traffic SRTP/UDP:1024-65535 Peer-to-peer /V session. SIP/MTLS/TP:5061 Director proxies Web traffic to destination pool s Web Service. E Office Web pps Server SM:445 VIS TP:5060 TLS:5061 ctive Directory SRTP/ UDP:49152-65535 Traffic goes directly to /V onferencing Service WITHOUT going through the pool s hardware load balancer Meeting content + metadata + compliance file share. File Share Server SRTP/ UDP:49152-65535 D VT UM 2015 Microsoft orporation. ll rights reserved. To send feedback about this documentation, please write to us at Sfdoc2015@microsoft.com.
RDP/SRTP/TP:49152-65535 pplication Sharing Peer-to-peer application sharing session SIP traffic: signaling SRTP: STUN/TP:443 RDP/SRTP/TP:1024-65535 HTTP(S) traffic RTP/SRTP traffic: /V onferencing IE traffic rrow direction indicates which ctual traffic is bi-directional. federation IE: STUN/TP:443 Source IP Destination IP Source Port Destination Port Port number to service traffic assignment: 5065 - pplication Sharing onferencing Service /V Edge ny ny /V Edge TP 50,000-59,999 ny ccess Edge - ccess Edge - SIP/TLS:443 SIP/MTLS:5061 SIP/MTLS:5062 SRTP: STUN/TP:443 IE: STUN/TP:443 SIP/MTLS MRS traffic HTTPS:4443 ctive Directory If client connects on port 80 during sign-in, it gets redirected to port 443 2015 Microsoft orporation. ll rights reserved. To send feedback about this documentation, please write to us at Sfdoc2015@microsoft.com.
TURN/TP:448 SRTP/RTP:49,152-57,500 Enterprise Voice ranch Office SIP traffic all dmission ontrol () traffic RTP/SRTP traffic: /V onferencing IE traffic rrow direction indicates which ctual traffic is bi-directional. SIP/MTLS:5061 SRTP/UDP:30,000-39,999 Media bypass: audio routed directly to gateway bypassing Mediation Server. MRS traffic Media codec varies per workload: RTudio, G.711, SILK SRTP/RTP:60,000-64,000 For federation, S connects directly with Director. If no Director is available, federation traffic goes directly to the Edge Server. ctive Directory If no Edge Server is defined in the topology, callee checks the Front End Server s andwidth Policy Service. WN onnection STUN/TP:448 SIP/MTLS:5061 Lync client automatically registers with the pool if the ranch ppliance becomes unavailable. ccess Edge - SIP/TLS:443 SIP/MTLS:5062 HTTPS:444 /V Edge IE: STUN/TP:443, STUN/UDP:3478 SIP/MTLS:5062 SIP/MTLS ranch ppliance onnectivity to: IP-PSTN gateway IP/PX Direct SIP SIP trunk Exchange UM,5070 SRTP/RTP:49,152-57,500 MRS traffic Enterprise Voice applications Port number to service traffic assignment: 5064 - Telephony onferencing Service 5067 Mediation Server Service 5071 - Response Group Service 5072 - onferencing ttendant Service 5073 - onferencing nnouncement Service 5075 - all Park Service Mediation Pool (optional) SIP/TP:5060,5061 2015 Microsoft orporation. ll rights reserved. To send feedback about this documentation, please write to us at Sfdoc2015@microsoft.com.
ertificate Requirements ore elements dditional elements Front End Pool Edge Servers Persistent hat Server Front End Server 1, Front End Server 2 FQDN: ertificate SN: ertificate SN: Root certificate: pool.<ad-domain> pool.<ad-domain> pool.<ad-domain>, fe.<ad-domain>, sip.<sip-domain>, lyncdiscoverinternal.<sip-domain>, lyncdiscover.<sip-domain>, admin URL, meet URL, dial-in URL, server private Edge Server 1, Edge FQDN: ertificate SN: Server 2 internal.<ad-domain> ertificate SN: internal.<ad-domain> server Root certificate: private network ccess edge /V edge onf edge network edge FQDN: access.<sip-domain> ertificate SN: access.<sip-domain> ertificate SN: access.<sip-domain>, sip.<sip-domain>, conf.<sip-domain> server Root certificate: public FQDN: ertificate SN: ertificate SN: Root certificate: chatsrv.<ad-domain> chatsrv.<ad-domain> N/ server, client private Director 1, Director 2 FQDN: dir.<ad-domain> ertificate SN: dir.<ad-domain> ertificate SN: Root certificate: private dir.<ad-domain>, sipinternal.<sip-domain>, sip.<sip-domain>, lyncdiscoverinternal.<sip-domain>, lyncdiscover.<sip-domain>, admin URL, meet URL, dial-in URL ranch ppliance Exchange UM Server Office Web pps Server FQDN: external Web Service FQDN ertificate SN: external Web Service FQDN ertificate SN: Root certificate: public FQDN: sba.<ad-domain> ertificate SN: sba.<ad-domain> ertificate SN: sba.<ad-domain> Root certificate: private FQDN: umsrv.<ad-domain> ertificate SN: umsrv.<ad-domain> ertificate SN: N/ Root certificate: private external Web Service FQDN, lyncdiscover.<sip-domain>, meet URL, dial-in URL, OwaExtWeb.<sip-domain> FQDN: OwaExtWeb.<sip-domain> ertificate SN: OwaExtWeb.<sip-domain> ertificate SN: wacsrv1.<ad-domain> ertificate SN: wacsrv2.<ad-domain> Root certificate: private 2015 Microsoft orporation. ll rights reserved. To send feedback about this documentation, please write to us at Sfdoc2015@microsoft.com.
SM:445 MS SM traffic HTTPS traffic rrow direction indicates which Subsequent traffic is bi-directional. Install on Enterprise Edition to provide high availability. Default (1433) or SQL named instance HTTPS:4443 TP:1433 The entral Management Store provides a robust, schematized storage of the data needed to define, set up, maintain, administer, describe, and operate a Skype for usiness Server deployment. It also validates the data to ensure configuration consistency. Enterprise Pool (MS master) ack-end SQL Server ll changes to this configuration data happen at the entral Management store, eliminating out-of-sync issues. Read-only copies of the data are replicated to all servers in the topology, including Edge Servers and Survivable ranch ppliances. The ctive Directory (D DS) are still used to store basic user information, such as the user s SIP URI and phone number. User policy information is stored in the entral Management store. The use of ctive Directory (D DS) also provides backward compatibility with earlier releases of Lync Server. To administer servers and services, you use Server Management Shell or the Server ontrol Panel, which then configure the settings in the entral Management store. The entral Management Server, which runs on one Front End pool or one Standard Edition server in your deployment, replicates the configuration changes to all of the servers in your deployment. Front-end Pool Mediation Pool ranch ppliance Director Standard Edition Server ctive Directory 2015 Microsoft orporation. ll rights reserved. To send feedback about this documentation, please write to us at Sfdoc2015@microsoft.com.
DNS onfiguration DNS onfiguration DNS Type /NME Value _sipinternaltls._tcp.<sip-domain> lyncdiscoverinternal.<sip-domain> Pool FQDN admin URL meet URL dial-in URL internal Web Services FQDN external Web Services FQDN Enterprise Edition Resolution pool FQDN individual FE IPs public IP address Standard Edition Resolution pool FQDN public IP address Purpose internal user access internal utodiscover Service pool name Lync Server ontrol Panel (LSP) Lync Server Web Service Lync Server Web Service Lync Server Web Service Proxied to Lync Server Web Service DNS onfiguration DNS Type /NME Value _sipfederationtls._tcp.<sip-domain> _sip._tls.<sip-domain> _xmpp-server._tcp.<sip-domain> sip.<sip-domain> ccess Edge FQDN: access.<sip-domain> /V Edge FQDN: av.<sip-domain> onf Edge FQDN: conf.<sip-domain> lyncdiscover.<sip-domain> meet URL dial-in URL external Web Services FQDN Resolution ccess Edge FQDN: access.<sip-domain> ccess Edge FQDN: access.<sip-domain> ccess Edge FQDN: access.<sip-domain> ccess Edge FQDN: access.<sip-domain> ccess Edge IP address /V Edge IP address onf Edge IP address Purpose Federation and public IM connectivity external user access XMPP federation locate Edge Server Edge Server ccess edge Edge Server /V edge Edge Server onf edge external utodiscover Service proxied to Lync Server Web Service proxied to Lync Server Web Service proxied to Lync Server Web Service OW DNS Type Value OW internal URL OW external URL Office Web pps Farm Resolution HL OW VIP public IP address Office Web pps Server Resolution OW server IP public IP address Purpose internal user access to PowerPoint Presentations external user access to PowerPoint Presentations 2015 Microsoft orporation. ll rights reserved. To send feedback about this documentation, please write to us at Sfdoc2015@microsoft.com.