working at e-office

Friday, November 30, 2007

Ask the expert..

Question(s):

since some weeks I follow your blog about OCS on unified-communications.blogspot.com and I appreciate your work very much.

I am desperatly looking for information about how OCS clients communication flows over the network:

For example a OCS user on a OCS server in Europe makes an IM communication with another OCS user on a OCS server in the same organization in the USA.

  • 1. I found that the SIP communication and the content oft he instant messages flows via the OCS servers and Video and Audio Streams flow directly from client computer to client computer?
  • 2. But how are Video and Audio streams for Live Meetings flowing And how are the streams for voice calls flowing? And how are those streams flowing for remote, federated and internet (=public IM) users?

Anwsers:

  • 1. That’s true SIP Communications are routed between the OCS infrastructure you deployed. While using TLS and default MTLS the flow is as follows. TLS and MTLS protocols provide encrypted communications and endpoint authentication on the Internet. Office Communications Server uses these two protocols to create its network of trusted servers and to ensure that all communications over that network are encrypted. All SIP communications between servers occur over MTLS. SIP communications from client to server occur over TLS.TLS enables users, through their client software, to authenticate the Office Communications Server 2007 servers to which they connect. On a TLS connection, the client requests a valid certificate from the server. To be valid, the certificate must have been issued by a CA that is also trusted by the client and the DNS name of the server must match the DNS name on the certificate. If the certificate is valid, the client trusts the server and opens the connection. The resulting connection is trusted and from that point is not challenged by other trusted servers or clients. Default this is port 5061 TLS port or you can configure port 443. Server-to-server connections rely on MTLS (Mutual TLS) for mutual authentication. On an MTLS connection, the server originating a message and the server receiving it exchange certificates from a mutually trusted CA. The certificates prove the identity of each server to the other. In Office Communications Server 2007 deployments, certificates issued by the enterprise CA are automatically considered to be valid by all internal clients and servers. In federated scenarios, the issuing CA must be trusted by both federated partners. Each partner can use a different CA, if desired, so long as that CA is also trusted by the other partner.
  • The following figure shows how Office Communications Server uses MTLS to create a network of trusted servers.
  • clip_image002
  • Office Communications Server 2007 uses TLS and MTLS to encrypt instant messages. All server-to-server traffic requires MTLS, regardless of whether the traffic is confined to the internal network or crosses the internal network perimeter. Requirements for client-to-client traffic depend on whether that traffic crosses the internal corporate firewall. Strictly internal traffic can use either TLS, in which case the instant message is encrypted, or TCP, in which case it is not.

image

  • But how are Video and Audio streams for Live Meetings flowing And how are the streams for voice calls flowing? The Video and Audio streams are redirected through your Edge infrastructure even to Federated partners. To get a good overview over which ports you need to open review. The first thing you need to do is consider which Edge infrastructure needs you have. When having that information review the OCS Edge Server deployment documentation.
  • When looking at Enterprise Voice is an implementation of IP telephony that uses SIP (Session Initiation Protocol) for signaling and RTP (Real-Time Transport Protocol) for voice. To get more controle over your Mediation Server and connections to a public PSTN cloud review my earlier post on how to configure the Mediation Server and Interoute see: post
  • 2. But how are Video and Audio streams for Live Meetings flowing And how are the streams for voice calls flowing? And how are those streams flowing for remote, federated and internet (=public IM) users?

clip_image004

Important notice about connections to PIM:

If you enable public IM connectivity, be aware that while communications between Office Communications Server and the public IM server are encrypted, communications between the public IM server and the public IM client might not be encrypted, depending on whether encryption is provided by the public IM provider.

 

Wednesday, November 21, 2007

Contact?

If you run Microsoft Office Live Communications Server 2005 SP1 or Microsoft Office Communications Server 2007 (hopefully ;-) and connected your AP or Edge servers to the internet... we can get in contact!

image

Step 1. Fill in my name joachim.farla@e-office.com (my SIP account is the same as my SMTP address)

image

Step 2. Drop me in your contact list! And live!

So, very simple! Do not hesitate to contact me by IM. I'am always in for a technical issue or just working things out generally. By the way you can also contact me through the public website of e-office at link

Consolidated edge server and interoute one?

Section: Enterprise Voice, Mediation Server

Today i've got an very good question about how to connect to interoute through OCS and how to configure the IP address etc.

Questions are:

1. Do you need a GW between your Mediation server and Interoute?

2. Have you ever configured a consolidated edge server – I am trying to do this with the least amount of kit – so what to put Access Edge /AV edge and Web conferencing on it – I have 3 separate IP addresses for the external interface but need to know if I can put all three on one NIC or if it is better to put the AV edge on one nic and the other two on the other.

Answers are:

1.No – the connection is direct between the mediation server and the Interoute One server

2. Our lab – (which was used as a pilot for 30 users) was on a consolidated edge server, with one public nic which worked fine.

For the office installation we have split the roles across two servers

  • 1/ A/V proxy
  • 2/ all other edge roles

This seems to be working ok for our 800 user installation – it was done this way for scalability and network infrastructure reasons (the A/V needing a non-natted public address). In all cases the machines involved had two nics – inside and outside….

Tuesday, November 20, 2007

UC Learning Path - Additional Resources

Related Trainings/Resources (not Core or Electives)

Type
Level
Title
Availability
Detail


200
Microsoft Office Communicator 2007 Tips
12/5/2007
N/A


300
Microsoft Office Communications Server 2007 Resource Kit
1/9/2008
Link

UC Learning Path - Electives


200
5126: Introducing Enterprise Instant Messaging Using Microsoft® Office Communications Server 2007
11/29/2006
Link


200
5127: Introducing On-Premise Conferencing Using Microsoft® Office Communications Server 2007
11/29/2006
Link


200
5128: Introducing Enterprise Telephony Using Microsoft Office Communications Server 2007
11/29/2006
Link


200
5129: Customizing Real-Time Communication with Microsoft® Office Communications Server 2007
11/29/2006
Link


200
6447: First Look: Getting started with Office Communications Server 2007
12/5/2007
N/A


200
Collection 5125: Introducing Microsoft® Office Communications Server 2007
11/29/2006
Link


200
TechNet Virtual Labs for Office Communications Server 2007
7/23/2007
Link


200
TechNet Webcast: Communicator Web Access for Communications Server 2007
5/9/2007
Link


200
TechNet Webcast: Implementing Instant Messaging/Presence and Conferencing in Microsoft Office Communications Server 2007
4/13/2007
Link


200
TechNet Webcast: Implementing Voice in Communications Server 2007
4/19/2007
Link


200
TechNet Webcast: Understanding Call Routing in Office Communications Server 2007
4/24/2007
Link


300
OCS 2007 Ignite Workshop
6/18/2007
Link

UC Learning Path - Core Training

Core training:

Required Trainings

Type
Level
Title
Availability
Detail


200
5177: Implementing and Maintaining Enterprise Instant Messaging Using Microsoft Office Communications Server 2007
12/12/2007
N/A


300
5178: Implementing and Maintaining Audio/Visual Conferencing and Web Conferencing Using Microsoft Office Communications Server 2007
12/12/2007
N/A


300
5179: Implementing and Maintaining Telephony Using Microsoft Office Communications Server 2007
1/7/2008
N/A