Forum Discussion
Chris_16805
Jun 25, 2012Nimbostratus
LYNC - Use F5 LTM as reverse proxy?
I have set up all the Lync pools and Virtual servers for LYNC as described in the F5 deployment guide on 10.2. We do not run TMG and don not want to so I need details on using the F5 to handle this process. I created a VS for port 8080 and another for 4443, configured them to pass traffic to the port 80 and 443 pools on my LYNC FE servers. Do I need an iRule to handle the URL "intelligence"? What else is needed as far as Certs or anything else?
Configuration is as follows, (all VLANS are on the one F5 LTM)
Firewall
|
F5 Untrusted DMZ Vlan (Edge server external interface)
|
Consolidated Edge servers
|
F5 Trusted DMZ Vlan (Edge server internal interface)
|
F5 Production Server Vlan
|
Front End Servers
Thanks
- mikeshimkus_111Historic F5 AccountHi Chris, this guide includes the steps you need to follow to use BIG-IP as a reverse proxy for Lync. It's for version 11 but the manual steps should be the same:
- Chris_16805NimbostratusThe guide asks for an internal and external IP for the reverse proxy. Can I just create an external virtual server and forward the ports to the individual FE servers in the pool?
- mikeshimkus_111Historic F5 AccountYou'd never go through the reverse proxy VIP on LTM to get to the Edge server, so I'm not sure why you're seeing that message.
- Chris_16805Nimbostratusno longer getting this error, but my meeting and dialin urls still don't work. When i go to my meet URL externally it redirects to the https url and then i get "the webpage cannot be displayed".
- mikeshimkus_111Historic F5 AccountI assume you are using the same cert and key on the external 443 VIP that you have configured in Lync for your web services, the Lync servers can connect to the Certification Authority and validate the cert, and that this external VIP is using a serverssl profile as well.
- Josh_41258NimbostratusChris,
- Robert_James_10NimbostratusSo the terminology here is confusing so I'm kind of lost. You show a firewall in front of your edge servers, do you have publically routable IP's on your Edge servers and VIP on the untrusted zone?
- Robert_James_10Nimbostratus2 Revesrse Proxies?
- Josh_41258NimbostratusRobert,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects