Hi there MSCRM community/experienced implementers,
We're trying to implement CRM 2013 (On-Prem) configured with Internet-Facing Deployment (IFD).
Our server scenario/setup (see attached image (Fig. 1)):
- 1 CRM Front-End Server (currently on DMZ)
- 1 CRM Back-End Server
- 1 AD FS Server (currently on DMZ)
- 1 SQL Database Server
The CRM 2013 Server Roles are NOT yet installed, and we’re about to.
The server (let’s call it CRMfrontend) where we will install the Front-End Server Role is on DMZ (perimeter network).
The server that will serve as AD FS Server is also on DMZ.
Questions:
1. How do I install the CRM 2013 Front-End Server Role to my CRMfrontend server if it’s on DMZ?
Because per requirements, the CRM Installation Account and Service Accounts are/must be members of the Active Directory Domain User group.
2. How do we implement/configure IFD if our CRM Front-End and AD FS Servers are on DMZ? How do they communicate with the internal servers?

Fig. 1 - VM Server Setup
Any input is greatly appreciated.
Thanks for your time and help!
ProgCRM