Forum Discussion
Vegas588_117701
Nimbostratus
Apr 18, 2013Lync 2013 Edge Config
I am new to F5 and recently helped a client deploy an LTM for Lync 2013. Lync 2013 has some very specific requirements when load balancing the Edge server. Specifically, I am interested in knowing wh...
mikeshimkus_111
Apr 18, 2013Historic F5 Account
Hi Vegas588, this blog post explains the best practices for Lync Edge w/F5: https://devcentral.f5.com/blogs/us/the-hopefully-definitive-guide-to-load-balancing-lync-edge-servers-with-a-hardware-load-balancer
Basically, the Edge needs to be able to see the real IPs of external clients so it can set up peer-to-peer connections between them, rather than proxy all the connections.
thanks
Mike
Phil_no_Spill_1
Nimbostratus
Nov 11, 2013Hi Vegas588,
I guess you've implemented now using Public IPs, however I have the same question and I'm a newbie to F5.
Can anyone confirm whether the below is supported or works... or if I'm talking horsedung.
I've seen posts by users saying that some have implemented F5 and Lync using NAT at the firewall successfully. We are going through the same issues, and are looking at redeploying the edge servers with Public rather than Private IPs to ensure a supported config.
My understanding is that if Lync is deployed and the "use NAT" option for AV services is enabled on the Edge Servers then provided the Edge server has a route out it "should work" using a private IP. AV Clients would connect using their Public IP to the Firewall assigned Public AV IP which nats to internal Edge server directly (bypassing the F5). Return traffic from the edge would embedd the public IP in the packet as its NAT aware. The Edge server would require a route back via the Firewall as SNAT isnt used.
The Access and Web Conferencing clients connect via the F5 to the edge using SNAT.
So the Firewall should be able to be set as the default gateway on the edge - whereas I've seen posts saying the Floating IP of the F5 DMZ should be the default gateway (which I don't get as this wouldn't forward unless it was setup to VIP back to the Firewall???).
Keen to here from anyone doing things this way.
Thanks - Phil
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects