Hi Tom,
Please check the below document for more details.
http://www.cisco.com/en/US/docs/telepresence/infrastructure/vcs/config_guide/Cisco_VCS_Microsoft_OCS_2007_R2_and_Lync_2010_Deployment_Guide_X7-1.pdf
check the appendix on page 101 and 102 it gives you a idea for your deployment scenario.
we recommend to use TLS between the VCS control and Lync server.
Although there are other things as well in the deployment which you might want to take care of like Lync server media encryption.
VCS can modify this SRTP headers if you have the Enhanced OCS collaboration key is installed. However this key is not required in every deplyoment scenario. If you have one call leg encrypted and other non-encrypted the B2BUA functionality will be able to take care of it.
As i said we recommend TLS and not TCP. In my lab i tried to make this connection using TCP but somehow i couldn't make it active. Although TLS work great in my lab. I found hard to troubleshoot the TCP connection!!
Also for the calls via external lync clients i would recommend to use the TURN service of expressway if you have option keys for TURN relay.
We recommend to use B2BUA as with OCS you might get problem related to video freez on lync client and using B2BUA will eliminate this problem.
Thanks
Alok