
Part II: Working with Server Roles
250
The second scenario, which is the one that is recommended , is where edge subscription and EdgeSync will
be performed. The following tasks are performed to fully integrate and associate the Edge Transport
server with the Exchange organization. This process ensures that the organization takes full advantage
of the message hygiene and anti - virus protection built into the Edge Transport server role. It also
requires the least administrative effort:
1. Ports: Verify that the perimeter network firewall that separates the Edge Transport server from
the Exchange organization is configured to enable communications on ports 25 and 50636.
Because EdgeSync replicates data between Active Directory and ADAM, secure LDAP port 50636
for TCP communication must be opened on the firewall to enable directory synchronization from
the Hub Transport to ADAM on the Edge Transport server. Recall that synchronization is single
directional, hence the port can be opened one - way from the Hub to the perimeter network. Also
verify that on the Edge Transport server, you can connect locally to the LDAP port 50389. This is
the port to access the ADAM instance. An easy way to test this is to use the ldp.exe utility found
in the
C:\WINDOWS\ADAM directory. Connect using the NetBIOS name of the Edge Transport
server and if no credentials are specified, it binds with ...