Installing a Lync server for a customer, and along with it a new TMG server as Reverse Proxy, I got a little reload on firewall requirements.
The customer did not have their perimeter set up as MSFT describes to be best practice, so that was also something to take care of in the process.
As the customer also was short on public IP addresses, the Edge was set up using only a single IP – discriminating services only through different ports on the external NIC. Documentation on this matter is a little scarce (see this article for some input), and since the TMG server is better off domain joined the official documentation on Lync falls short as to specify what firewall exceptions are needed for that.