This has been tested with
Primary Name: lync.<your domain FQDN> Subject Alternate Name(s) SAN lyncuag.<your domain FQDN> lync.<your domain FQDN> dialin.<your domain FQDN> meet.<your domain FQDN> lyncdiscover.<your domain FQDN> lyncweb.<your domain FQDN>
External DNS Requirements (including Edge entries) lyncuag.<your domain FQDN> (A record) – UAG External IP lyncweb.<your domain FQDN> (A record) – UAG External IP lyncdiscover.<your domain FQDN> (CNAME) – (lyncweb.<your domain FQDN>) sip.<your domain FQDN> (A record) – Edge External IP (used for Edge deployment separate to UAG) sipexternal.<your domain FQDN> (CNAME) – (sip.<your domain FQDN>) (used for Edge deployment separate to UAG) _sip_tls.<your domain FQDN> (SRV) record Port 5061 (used for Edge deployment separate to UAG)
1. Start ForeFront UAG. 2. Right-Click HTTPS Connection and select New Trunk 3. Name the Trunk and enter the public hostname and IP address (this should match the DNS record created i.e. lyncuag.<your domain FQDN>) – this name should be different to the external name of the Lync Front End Pool. Click Next 4. Select the Authentication Server for your domain by clicking Add. Click Next. 5. Select the Public Certificate you have obtained. Click Next. 6. Select the default option of Use ForeFront UAG access policies. Click Next. 7. Select the Default Endpoint Policies. Click Next. 8. Click Finish.
1. Select the trunk created above. 2. Click Add under Applications. 3. Click Next 4. Select Microsoft Lync Web App 2010 under Web. Click Next. 5. Enter a name for the application (i.e. LyncWeb). Click Next. 6. Leave the Endpoint Policies as default. Click Next. 7. Click Next. 8. Enter lyncweb.<your domain FQDN> under Addresses. This should resolve to the Front Edge (or Director) Server from the UAG server. This should also match the name that External Access URL is set in the Lync Topology. Enter the same public host name. Click Next. 9. Uncheck Use SSO. Click Next. 10. Remove “dialin” from Application URL. Click Next. 11. Click Finish.
1. Click Configure under Trunk Configure. 2. Select the Authentication tab. Uncheck Require users to authenticate at session logon. 3. Select the Session tab and check Disable component installation and activation and Disable scripting for portal applications. 4. Click OK.
(Warning Serious problems might occur if you modify the registry incorrectly by using Registry Editor or by using another method. These problems might require that you reinstall the operating system. Microsoft cannot guarantee that these problems can be solved. Modify the registry at your own risk.) 1. Open Registry Editor 2. Navigate to HKLM\Software\WhaleCom\e-Gap\von\UrlFilter 3. Right-Click and add a DWORD 32-bit registry KeepClientAuthHeader and set the value to 1. 4. Close the registry editor.
1. Click the Save button in the UAG console. 2. Click Activate 3. Once the configuration has completed, click Finish 4. Start a Command Prompt (cmd) as Administrator. 5. Perform and IISRESET.