Hi JinDeep,
Based on my research, you should keep both roles in Single zone, because internal environment, external environment and DMZ are in the different Network Zone, you do not set another Network Zone for your internal environment.If you want to know more
details about the port, you could refer to
this link.
Required Server Ports (by Server Role)
Mediation Servers
|
Skype for Business Server Mediation service
|
5070
|
TCP
|
Used by the Mediation Server for incoming requests from the Front End Server.
|
Mediation Servers
|
Skype for Business Server Mediation service
|
5067
|
TCP (TLS)
|
Used for incoming SIP requests from the PSTN gateway.
|
Mediation Servers
|
Skype for Business Server Mediation service
|
5068
|
TCP
|
Used for incoming SIP requests from the PSTN gateway.
|
Mediation Servers
|
Skype for Business Server Mediation service
|
5070
|
TCP (MTLS)
|
Used for SIP requests from the Front End Servers.
|
Hardware Load Balancer Ports if Using Only Hardware Load Balancing
Mediation Server load balancer
|
5070
|
TCP
|
Front End Server load balancer (if the pool also runs Mediation Server)
|
5070
|
TCP
|
Recommended IPsec Exceptions
Mediation Server Inbound
|
Any
|
Mediation Server(s)
|
UDP and TCP
|
Any
|
Any
|
Do not authenticate
|
Mediation Server Outbound
|
Mediation Server(s)
|
Any
|
UDP and TCP
|
Any
|
Any
|
Do not authenticate
|
Best Regards,
Leon Lu
Please remember to
mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact
tnsf@microsoft.com.
Click
here to learn more. Visit the dedicated
forum to share, explore and talk to experts about Microsoft Teams.