280 likes | 365 Views
INF315 - Live Communication Server 2005 Technological Drill Down. Golan Edri RTC Regional Director Artnet Experts golane@office.artnet.co.il. Agenda. Architecture-Overview Capacity Planning Demo Remote Access Solutions Demo Archiving Services Demo
E N D
INF315 - Live Communication Server 2005TechnologicalDrill Down Golan Edri RTC Regional Director Artnet Experts golane@office.artnet.co.il
Agenda • Architecture-Overview • Capacity Planning • Demo • Remote Access Solutions • Demo • Archiving Services • Demo • Live Communication Server- Security • Resource Kit • Demo,Demo,Demo,Demo,Demo,Demo
Proxy Access Proxy Server Roles Enterprise Pool Director Archiving Service Address Book Service
Enterprise Edition Server • Two Tiered Architecture - Over 120k users in single pool - SQL database stores user info • Scale out - With additional EE servers and hardware load balancer • For Higher Availability - Front End fail-over support - Optional SQL clustering
Load balancer Load balancer Internet Access Proxy • New server role in Live Communications Server 2005 • Deployed in the network perimeter (DMZ) • Controls Federation and Remote Access settings • Message Security • Certificates required • Traffic is always encrypted (TLS) Corporate Network
Proxy • Functionality • forward client requests • Does not • host users • perform authentication • enable federation
AB AB AB Address Book Service AD File Server UR syncs from AD file://internal/share Normalize http://external/path Address Book Service ABS syncs from LCS User Replicator (UR) ISA 2004
MSMQ MSMQ Archiving Service • Archiving Agent / Archiving Service • MSMQ • SQL Server 2000 SP3a+ • Per-user archiving • Global default • User overwrite • Federation notification header (MOC)
Archiving Service • Archiving Service Settings • Retrieving and IM session
Capacity Planning Tools • Live Communications Server System Model • User Load Simulation Tool- LcsUserStress • Backend Load Simulation Tool-LcsLoadSim No LCS Required
Configure CapacityPlanning • LCSStressUser Simulation • LCSLoadsim Simulation • Bottle-neck detection situation
Remote Access Solutions • Remote User Topology • Enterprise to Enterprise Federation
Remote User Concepts • YOUR enterprise users, connecting from home or any external network • Without a VPN • Not users (e.g. No AD in the perimeter network) • Features • Presence, IM, User Search, Roaming Contacts • Voice/Video/Data limited by Firewall • Third party- Jasomi,Ingate,Netrake Solutions
Remote User Topology Firewall port 443 or 5061 Office Communicator Trusts the CA of the certificate used by the AP DMZ TLS Director Pool MTLS MTLS Web Client Access Proxy AD Office Communicator Mobile
Remote User Access • Mobile Communicator • Web Client Access
Enterprise A Enterprise B MTLS AD AD MTLS MTLS LCS 2005 LCS 2005 LCS 2005 Access Proxy LCS 2005 Access Proxy LCS Clients LCS Clients General Federation Concepts • Enables secure communication with other enterprise LCS deployments • Instant Messaging/Presence • Full admin control • Archiving notification
Configure Direct Federation • Enable Federation • Specify Domain to Federate with … • Cross Certificate
Group Policy (rtcclient.adm) Security related policies • Prevent computer-to-computer audio calls • Prevent computer-to-phone audio calls • Prevent video calls • Prevent file transfer • Specify encryption for computer-to-computer and audio/video calls IMFilter.am • A script that runs on internal servers to: • Block file transfer • Block any IM which contains a clickable URL • Disabled by default Intelligent Instant Message Filter • Enhanced URL filtering • Enhanced file filter control
Resource Kit Tools • Lcsping - Check Connectivity Servers • Lcscheck - Reports warnings an errors • lcswizard - Step-by-Step configuration • Lcsdiag - Diagnostic tool • Lcscertutil - Request Server Certificate
Summary • Architecture-Overview • Capacity Planning • Demo • Remote Access Solutions • Demo • Archiving Services • Demo • Live Communication Server- Security • Resource Kit • Demo, Demo, Demo, Demo, Demo, Demo
Thank You Golan Edri RTC Regional Director Artnet Experts golane@office.artnet.co.il