Introduction This post is about a recent scenario where TMG Administrator was receiving complains that some workstations that were using TMG as proxy were failing to run Windows Update. The interesting part of this issue was that only some workstations were having such problem and only if they were using “Automatic Detection” settings (which use WPAD). But all other workstations were using the same setting and were working just fine.
Data Gathering In order to troubleshoot this I started TMG Data Packager in repro mode using Web Proxy and Web Publishing template and performed the following steps in the client workstation that was having the issue:
Data Analysis I started the data review by looking to the TMG Logging and notice that when it failed the following URL was sent it back to the client:
Notice that this URL returns the error -2145107946 (in decimal), which corresponds to 0x80244016 (in Hex), which means the following:
WU_E_PT_HTTP_STATUS_BAD_REQUEST wuerror.h # Same as HTTP status 400 - the server could not process the # request due to invalid syntax.
Having that info, it was time to review the netmon trace to understand why the request was invalid and after reading the trace, it was possible to understand why it was invalid.
Conclusion By using Netmon it was possible to see the moment that client downloads the WPAD file and tries to access the TMG. But, in it can’t access for some reason (in this case it was a networking routing issue) and switches to another TMG. I wasn’t aware that this environment had another TMG, so I opened the WPAD file and found the following entry called BackupRoute:
BackupRoute="FFTMGEEN2.contoso.com"; UseDirectForLocal=true; ConvertUrlToLowerCase=false;
This was a backup TMG that was supposed to be used only if the main one was down. So the problem here was:
Solution In order to fix this it was necessary to change the entry on the Alternate Forefront TMG field within TMG console to be as shown below:
Once this change was done, the WPAD file changed to have the following entry on the backup route:
Have a happy Windows Update process behind TMG !!
Author Yuri Diogenes Senior Support Escalation Engineer Microsoft CSS Forefront (ISA/TMG) Team