Lync 2013 Enterprise load balancing on the front end and edge pool

Hi,
I am setting up a Lync 2013 Enterprise deployment consisting of a Front End pool (x2 FE servers) and an Edge pool (x2 Edge servers).  I'm seeing some conflicting advice regarding load balancing using hardware or DNS for the front end and the edge.
On the front end I have 2 internal DNS records 'lyncfepool1.contoso.local' each of which map to one of the IPs of the FE servers.  I've used my details to populate the Detailed Design Planner excel spreadsheet and am told that I require a HLB to load
balance my front end pool.  I'm aware of the need to load balance HTTPS traffic internally (which will be done by TMG) however other traffic to the front end (SIP, etc) can be balanced by DNS only, and not require a HLB?
Can someone clarify the front end requirement?
Also - looking now at the edge pool - this site again have two edge servers in a pool.  We are using a total of six private IP addresses, two per edge service (2 x av.contoso.com, 2 x sip.contoso.com and 2 x webcon.contoso.com).  These will be
NAT'ed by the external firewall and directed to the respective external (DMZ) IP addresses on the Edge servers on port 443.  I know this isn't true roundrobin due to the intelligence of the Lync client when connecting (in that the Lync client will connect
to one of the public IPs and if it can't connect, it will know to connect to the other service IP), however I want to clarify this set up, particularly the need to direct the external public IP traffic at the DMZ Edge IP specified in the topology builder.
I've attached a basic diagram of the external/DMZ/Edge side which hopefully helps with this question
Persevere, Persevere, Per..

That is because you will always need HLB for a front-end server since it hosts the Lync webservices which use HTTP/HTTPS traffic.
The description on the calculation tool also describes this correctly:
Supports Standard and Enterprise pools (up to 12 nodes), with pure device-based load balancing or a combination of DNS load balancing and device-based load balancing (for
Lync web services)
You can use either Hardware or DNS loadbalancing for SIP traffic only, but you will always need a HLB for the webservices.  Both are applicable for the Front-End so you have either
full HLB for both SIP and HTTP(S) traffic
DNS LB for SIP traffic and HLB for HTTP(S) traffic
Hope this is more clear :-)
Lync Server MVP | MCITP Lync Server 2010 | If you think my post is the answer to your question, please mark it as answer so future visitors can easily find it.

Similar Messages

  • Lync Front End and Edge on same host

    Hey guys can anyone confirm if having a front end and edge on single host is supported, providing of course the ram and cpu requirements are met.
    Thank you.

    The Front End and Edge must be on separate computers and can't be collocated. Both servers can coexist on the same Virtual Host if using VMware or Hyper-V.
    See: http://technet.microsoft.com/en-us/library/gg398131.aspx
    Please mark posts as answers/helpful if it answers your question.
    Blog
    Lync Validator - Used to assist in the validation and documentation of Lync Server 2013.

  • Hello there, I am creating a database of all our companies press contacts. I would like to create a form that would act as the front end and feed the database which is obviously the back end. The database is in Access 2013. My question is to whether this

    Hello there, I am creating a database of all our companies press contacts. I would like to create a form that would act as the front end and feed the database which is obviously the back end. The database is in Access 2013. My question is to whether this is indeed possible?

    This forum thread appears to point towards the problem.
    Re: Unable to Switch Audio Sync Settings

  • Configuring Lync 2010 Mobility with Front end and Edge Server

    I have been racking my brain the past week trying to figure out how to get the lync edge server working properly and how to get the mobility service working properly.
    Currently I have 1 front end server that is configured and working.  I have one edge server that has been configured according to nearly every online help I could find along with public CERT.
    If I use microsoft's online connectivity test and I run the test for
    Lync Server Remote Connectivity Test everything passes.  I am also able to connect to lync using a windows lync client from outside of the internal network however I have to specify the server name as being sip.ourdomain.com I cannot get connected using
    autodiscover.
    When I run the Lync Autodiscover Web Service Remote Connectivity Test it fails due to SSL error to lyncdiscover.ourdomain.com which then lead me down the path that I needed to install
    the Mobility service but it also tells me that I may need to update our SSL cert as well.
    This is where I am getting confused and would like to be pointed in the correct direction.
    When I installed mobility service on the front end server it created the autodiscover section in IIS.  If I am inside our network I can browse to it without any issue.  Where I am confused at this point is how to either setup DNS or how to configure
    the edge server to use autodiscover.
    Do I need to setup an additional public IP and point lyncdiscover.ourdomain.com to the IP of our front end server or to our edge server?  If I have to point this to our front end server then that would mean that I use one public IP that goes to 443,
    444 and 5061 for our edge server and then I would need one public IP that goes to ports 443 and 80 that get redirected to ports 4443 and 8080 on our front end server?  If that is the case then do I have to get an external cert for the front end server
    that contains lyncdiscover or can clients connect if it is just using the self signed cert from the domain?
    This is where I am getting confused at and hopefully some nice folks out there can clarify this for me so I can get this resolved.
    Thank you
    KK

    You need an additional public IP to point to a reverse proxy, which will listen on port 443 and proxy requests to your front end server on port 4443 (notice the extra 4).  You can use IIS ARR, Web Application Proxy, or whatever else you may have for
    this purpose, but you need to ensure you redirect port 443 to port 4443.  This reverse proxy cannot be collocated on your front end server or edge, you'll need a separate box or appliance. 
    Beyond Lyncdiscover, you'll want to do this for your external web services FQDN as defined in the topology builder and your meet and dialin URLs too.  You'll want a third part cert for all of this (though it doesn't need to be installed on the front
    end, just the reverse proxy) so that you don't need to install any internally signed root certs on anyone's smartphone.
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications
    This forum post is based upon my personal experience and does not necessarily reflect the opinion or view of Microsoft, its employees, or other MVPs.

  • Lync 2010 Standard Edition Front-End and Edge Cerificate Renewal issue

    Hi Experts,
    I have a client with Single Standard Edition FE server and 1 Edge server and both are using PUBLIC certificates. It also has a reverse-proxy server (F5 HLB) with wildcard certificate installed. The FE and Edge certificates are about to expire and the client
    now wants the ff.
    1. Internal Certificate from Internal CA server for FE
    2. External Certificate from Public CA for Edge
    What I did was,
    A. For Internal Cert - I generated a CSR from MMC cert manager using custom request from the FE server and have it signed by the Internal CA. Reason I did that was, everytime I requested the CSR from Lync Certificate Wizard, it is getting the certificate
    template not supported by the Internal CA.
    B. For External Cert - I requested the Edge external CSR thru Lync Certicate Wizard and submitted to the client for public CA renewal.
    When I installed both certificates, internal lync works fine but anything external (i.e. external lync access, mobile, federation) do not work anymore.
    So I decided to roll back the certificates and everything went back to normal?
    Question is, what steps or process did i miss or gone wrong? Hope for your response. Thank you in advance.

    Hi DaxZilla,
    You also need to request a certificate to internal interface of Edge Server from internal enterprise certificate authority.
    The certificate for the external edge interface should contain SANs as below:
    SAN=Access Edge service FQDN
    SAN=Web conference service FQDN
    SAN=SIP domain FQDN
    Mobile client goes through reverse proxy server to sign in. It is not related with Edge Server. Check the certificate on reverse proxy is not expired.
    Best Regards,
    Lisa Zheng
    Lisa Zheng
    TechNet Community Support

  • How to place an image in database and how to retrieve and display it in the front end

    how to place an image in database and how to retrieve and display it in the front end
    and to place an image in database and retrieve the image from database using xml
    please,help me out.

    Create a table with a Long RAW Datatype column for storing the Image Column Data.
    Create the form based on the table , which by defaults the column with LONG RAW atatype to a Image Item.
    You can use Forms Built in function READ_IMAGE_FILE to read a Image file stored on the file system in to the image item.
    A save on the form saves the image in the Image item in the long raw column.

  • To change the layout of the front end

    I am working in c projects it is a web enabled server at the front end and at the back end it is sap
    I have to make changes in front end to add two i/p fields and backend it should update the sap table
    Please help
    Regards
    Abhijit Chitre

    Hi,
    Welcome to SDN.
    Could you give us information about the web application on the front end, is it using BSP ?
    It sounds like you want to modify the standard, is that OK for you ?
    Have you already located the BSP application (if any) in charge of the processing ?
    Best regards,
    Guillaume

  • Lync Discover Internal Load Balance

    I have tried using DNS and hardware load balancing for the lyncdiscoverinternal A record,
    If I disable the NIC on one of my 2 front end servers in my pool that the client is connected to it gets signed out,
    the client does not then sign back in for about 2 minutes.
    Can someone explain why the client takes so long to try another server in the pool and re-try the signing to a different FE server as 2 minutes is too long...
    I have 2 servers in a pool called pool.domain.com and the srv record points to pool.domain.com
    I have 2 A records for pool.domain.com pointing to each FE server
    I also have a director pool, will pointing the pool.domain.com srv record for _sip to this pool improve failover speed?
    ***Don't forget to mark helpful or answer***

    i tried doing the full HLB method (using f5) and during testing it seems lync itself doesnt want to support that (which is why microsoft recommends DNS AND HLB i am betting).  What i saw in my testing was after the node you were on was "failed" the
    lync client went to its secondary via the list of servers it gets when it first connects, so instead of connecting to the VIP of the HLB, it connected directly to a front-end server that was listed as secondary for that user at that point.
    Doing the combination of HLB and DNS LB, the time it takes for the client to connect seemed to be much less (under 10 seconds in my tests).  I hate that i have to use both technologies, if they are going to force you to use HLB (for web servcies), they
    should let everything work via that method...

  • Enterprise Load Balancer

          Dear Team,
    I would like to know about Enterprise load balancer best hardware and software which is recommended for cisco devices and how its work in Enterprise network where i have 3 ISP , actually i want to implement this in our infrastrusture.
    Kindly help   
    hari       

    You have to remember that the 9.0.4 release isn't that new either. However, you can basically use every load balancer out there if they support 1) Sticky/Persistent sessions and 2) Nat client.
    You may also want to check this link:
    http://www.oracle.com/technology/products/ias/hi_av/Tested_LBR_FW_SSLAccel.html
    Regards,
    Martin

  • Flash media server 4 enterprise load balancing

    G'day chaps, me and my mates have purchased a copy of Flash Media Server 4 Enterprise edition for use on our web project.  Since we will be transmitting to large amounts of users through this exceptional piece of software, we will be needing to run more than one server at once.  Before going ahead and doing anything against the policies we have decided to post here on the support forums and inquire about being able to run multiple copies of Flash Media Server 4 Enterprise edition with one Serial KEY ( 10 x GigE dedicated servers ).  If this is not possible, how can me and my chappies load balance all the traffic through one Flash Media Server 4 Enterprise edition.

    Hi there bluray,
    Congrats on your FMES purchase - we really hope FMS meets all your needs.  Although you'll not be permitted by your license to use it for more than one server installation you should be aware that FMS 4 has new scalability functionality that should enable you to scale beyond what you're currently expecting.  You may want to get immediately familiar with RTMFP and peer assisted networking.   FMS has the capability to serve as your personal introducer leveraging the power of peer to peer to scale more massively than a single installation is capable of.
    Here's a little snippet about it
    http://www.adobe.com/devnet/flashmediaserver/articles/p2p_rtmfp_groups.html
    or
    http://en.wikipedia.org/wiki/Real_Time_Media_Flow_Protocol
    Hope that helps.
    Asa

  • Web Dispatcher not doing the load balancing on the portal

    Hi Experts
    I am having a production issue where the SAP web dispatcher is not doing the load balancing on the portal.
    We have ESS/MSS portal with 1 Message server and 2 Application servers. The Web dispatcher is installed on the message server itself. Here is my Web disp profile file
    Profile generated by sapwebdisp bootstrap
    unique instance number
    SAPSYSTEM = 16
    add default directory settings
    DIR_EXECUTABLE = .
    DIR_EXECUTABLE = F:\usr\sap\<SID>\sapwebdisp
    DIR_INSTANCE = .
    Accessibility of Message Servers
    rdisp/mshost = <hostname>.com
    ms/http_port = 8111
    #Log and Trace
    rdisp/TRACE = 2
    SAP Web Dispatcher Parameter
    wdisp/auto_refresh = 120
    wdisp/max_servers = 100
    wdisp/shm_attach_mode = 6
    configuration as per SAP note 538405
    icm/max_conn      = 7000
    icm/max_sockets   = 14000
    icm/req_queue_len = 6000
    icm/min_threads   = 100
    icm/max_threads   = 300
    mpi/total_size_MB = 500
    mpi/max_pipes       = 14000
    wdisp/HTTPS/max_pooled_con = 7000
    SAP Web Dispatcher Ports
    icm/server_port_0 = PROT=HTTP,PORT=8888
    SSL
    icm/server_port_1 = PROT=ROUTER,PORT=443, TIMEOUT=60
    SAP Web Dispatcher Web Administration
    icm/HTTP/admin_0 = PREFIX=/sap/wdisp/admin,DOCROOT=./admin,AUTHFILE=icmauth.txt
    wdisp/enable_j2ee_groups = TRUE
    wdisp/HTTPS/sticky_mask = 255.255.255.255
    In my Web dispatcher Admin page, I see all the three application servers, however the requests are going to only 1 App server. We are using ENd to End SSL configuration for the web dispatcher.
    We also have a reverse proxy in the landscape and reverse proxy is forwarding all the requests to the Web dispatcher. In Web disp Admin page>Dispatching Module>SSL End to END dispatching, I see only ONE table entry in the dispatching table and it is our Reverse Proxy.
    As all the requests are coming from only one source (Reverse proxy), it seems to me that the sap web dispatcher  is forwarding those to the same Application server every time.
    Can anyone please advise ?
    I also tried to configure logon group in NWA, the web dispatcher is detecting the logon group and all the app servers in the logon group. It still not doing the load balancing.
    I would greatly appreciate any help.
    Thanks
    Viny

    Vincent, can you please elaborate more ?  Is the web dispatcher not able to recognize stateful and stateless application requests ?
    I saw that the procedure for configuring SSL Termination on Web dispatcher is long and complicated and looks like SAP web dispatcher needs to have SSL certificate of its own. As we have no ABAP servers and only Java servers, I can not even create the PSEs using STRUST (as described in SAP help -http://help.sap.com/saphelp_nw70ehp1/helpdata/en/48/99c388d7c46bb9e10000000a42189d/frameset.htm
    We already have SSL certificates for Java App servers.
    I suppose there should be a way for web dispatcher to identify the incoming requests and forward to appropriate application servers.
    Any help is much appreciated.
    Thanks
    Viny

  • Cache and Load Balancing for the Oracle APEX Listener

    Hi,
    I intend to use only HTTP access.
    My database is Oracle 11gR2, SE, 32 bit.
    How to implement a Cache and Load Balancing with the Oracle APEX Listener?
    Is it possible to do with the the standalone running APEX Listener?
    Thanks by advance for any tips/documentation/references.
    Kind Regards.

    Error. To be closed.

  • Load-balancing in the same IP subnet

    Can I use load-balancing in the same IP subnet? I have the servers and client in the same IP subnet. I'd like to load-balance client traffic to server traffic. I also need to load balance traffic between servers. Is possible to configure it only in one VLAN?
    For example:
    CSS:
    interface 4/2
    circuit VLAN1
    ip address 10.0.0.10 255.255.255.0
    service s1
    ip address 10.0.0.101
    active
    service s2
    ip address 10.0.0.102
    active
    service s3
    ip address 10.0.0.103
    active
    service s4
    ip address 10.0.0.104
    active
    owner test
    content client
    vip address 10.0.0.3
    add service s1
    add service s2
    active
    content servers
    vip address 10.0.0.4
    add service s3
    add service s4
    active
    Cat6500:
    interface FastEthernet4/1 - clients
    no ip address
    switchport
    switchport mode access
    spanning-tree portfast
    interface FastEthernet4/2 - servers
    no ip address
    switchport
    switchport mode access
    spanning-tree portfast
    interface FastEthernet4/3 - CSS
    no ip address
    switchport
    switchport mode access
    spanning-tree portfast
    interface Vlan1
    ip address 10.0.0.1 255.255.255.0
    ip policy route-map pokus
    access-list 101 permit tcp any eq 80 any
    route-map pokus permit 10
    match ip address 101
    set ip next-hop 10.0.0.10
    Thank you
    Roman

    yes, it's possible - use trunk with two VLANs (slide 9). or you can use 'transparent' mode (slide 11 - your attachment).
    answer to your question (I have the problem to understand why there are two links with the same VLAN on the picture):
    on the switch are two port interfaces in *switchport* mode (not trunk). now is it clearly?
    result:
    both methods (bridge mode with two vlans, or transparent bridge mode) use two vlans. it's on you, which type is for you preferred.
    my recommendation is - use first method - one link to CSS with trunk configured in bridge mode (one ip subnet, two vlans, default gw for servers isn't css, but parent router)
    martin

  • Load balancing by the proxy plugin

    Has anyone encountered this before:
    I have a cluster of two WLS 5.1 servers, hosting servlets that serve web
    requests. The requests are proxied through a web server ( I have tried
    Weblogic, Apache as well as IIS). I also have a tool that simulates
    concurrent web requests and fires them to the proxy server.
    As per documentation, as the load balancing while proxying requests to
    servlets is round robin, I expect that the requests are uniformly
    distributed across the two weblogic servers. But what I see is a bit
    different. In one case I fired 15 requests and found that 11 went to first
    server and 4 went to the other.
    Second time when I fired again 2 of them went to the first server and 13 to
    the second one. I would expect that around half of the total requests
    should be routed to each server everytime so that there is a proper load
    balancing done by the proxy. I have not changed any configuration related
    to the default load balancing algorithm. So I expect it is round-robin.
    Has anyone encountered this before ? This happens to me irrespective of
    which proxy server I use (i.e which proxy plugin I use). Is there some
    other configuration required and I am missing something or is there some
    inherent problem with the load balancing of the proxy plugins. Any info
    would be highly appreciated.
    Thanks
    Mainak

    Could you post this in weblogic.developer.interest.plug-in? This group is for
    ejb related questions. Thanks.
    Bill
    Mainak Datta wrote:
    Has anyone encountered this before:
    I have a cluster of two WLS 5.1 servers, hosting servlets that serve web
    requests. The requests are proxied through a web server ( I have tried
    Weblogic, Apache as well as IIS). I also have a tool that simulates
    concurrent web requests and fires them to the proxy server.
    As per documentation, as the load balancing while proxying requests to
    servlets is round robin, I expect that the requests are uniformly
    distributed across the two weblogic servers. But what I see is a bit
    different. In one case I fired 15 requests and found that 11 went to first
    server and 4 went to the other.
    Second time when I fired again 2 of them went to the first server and 13 to
    the second one. I would expect that around half of the total requests
    should be routed to each server everytime so that there is a proper load
    balancing done by the proxy. I have not changed any configuration related
    to the default load balancing algorithm. So I expect it is round-robin.
    Has anyone encountered this before ? This happens to me irrespective of
    which proxy server I use (i.e which proxy plugin I use). Is there some
    other configuration required and I am missing something or is there some
    inherent problem with the load balancing of the proxy plugins. Any info
    would be highly appreciated.
    Thanks
    Mainak

  • Load balancing in the process chains

    HI friends
    I have 6 subchains in 1 metachain . we are facing a problem  where we have to 2 servers . but when we run the process chains they are  occuping all the DIA process  in only one server . the other server is empty . so is there a way  that we can do the load balancing in the process chains . so that the process chains can occupy all the resources in both servers than only one . please do reply . this is very important . thankyou  for all your replies .
    *Points will be rewarded *.

    Hi,
    check this out: https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/com.sap.km.cm.docs/oss_notes/sdn_oss_bc_ccm/~form/handler
    additionally some information.
    You can specify a server on which the chain will run, but this is not really load balancing. Load balancing must be set up by a basis person.
    regards
    Siggi

Maybe you are looking for

  • Apple mobile device failed to start during download

    apple mobile device failed to start during download

  • Itunessetup.exe is not a valid win32 application?

    I am trying to install the newest version of iTunes, but no matter what I try, the same error message comes up and won't let me install -- itunessetup.exe is not a valid win32 application. What do I do? Thanks.

  • Query related to Dead Stock

    Hi, What is Dead Stock and How to determine the material, that is it Dead Stock or not??? If we run the Tcode MC50, it shows the Dead Stock data like: - Material...................Short text...................Dead stock value...................% ....

  • Changing Package Session's Status to Warning

    Dear Experts, How do I change my package session's status to warning? I created a package and errors handling in the package, after the package is executed it will always be flagged as Success in the ODI Operator. How do I change the package status t

  • Ipod mini not recognized.....

    Having problems with my ipod mini 1st. it wouldnt updload it only uploaded 10 songs then 57 then 173 and then 220 and then it froze (i know how to restart it) i have 800 songs that need to be uploaded 2nd. my computer wont recognize it i wanted to re