<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US"><title type="html">Forefront TMG Product Team Blog</title><subtitle type="html" /><id>http://blogs.technet.com/b/isablog/atom.aspx</id><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/" /><link rel="self" type="application/atom+xml" href="http://blogs.technet.com/b/isablog/atom.aspx" /><generator uri="http://telligent.com" version="5.6.50428.7875">Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><updated>2013-01-17T16:14:00Z</updated><entry><title>TMG Service recovery actions</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/06/10/tmg-service-recovery-actions.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/06/10/tmg-service-recovery-actions.aspx</id><published>2013-06-10T10:40:14Z</published><updated>2013-06-10T10:40:14Z</updated><content type="html">&lt;p&gt;If the Firewall service crashes a number of times within a short time period it does not automatically restart after the 4&lt;sup&gt;th&lt;/sup&gt; crash. If you review the Service Control Manager settings for the Firewall service appears to be configured to restart after all failures.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/4478.clip_5F00_image001_5F00_785F2E6E.png"&gt;&lt;img title="clip_image001" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="clip_image001" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1526.clip_5F00_image001_5F00_thumb_5F00_56FF88D2.png" width="372" height="419" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;After each of the first three failures, you will see this error in the event log:&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Log Name:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; System     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Source:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Service Control Manager     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Date:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 3/4/2013 1:36:24 PM     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Event ID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 7031     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Level:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Error     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Computer:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; TMG.domain.local     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Description:     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;The Microsoft Forefront TMG Firewall service terminated unexpectedly.&amp;#160; It has done this 3 time(s).&amp;#160; The following corrective action will be taken in 60000 milliseconds: Restart the service.&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;This is inline with the expected behavior.&lt;/p&gt;  &lt;p&gt;However, after the fourth failure the service will no longer restart and you will see this error in the event log:&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Log Name:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; System     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Source:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Service Control Manager     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Date:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 3/4/2013 1:45:34 PM     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Event ID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 7034     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Level:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Error     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Computer:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; TMG.domain.local     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;Description:     &lt;br /&gt;&lt;/i&gt;&lt;i&gt;The Microsoft Forefront TMG Firewall service terminated unexpectedly.&amp;#160; It has done this 4 time(s).&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;The behavior may appear inconsistent and unexpected but it is actually by design.&lt;/p&gt;  &lt;p&gt;During the TMG installation, the service is configured to only automatically restart after the first 3 crashes in a 24 hour period in order to raise the attention of the system administrator that something is going wrong with this service that needs investigating. This can be considered similar to IIS Rapid Fail Protection to avoid a situation where we are restarting and then crashing straight way&lt;/p&gt;  &lt;p&gt;By checking the service configuration in the registry key, HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fwsrv we can see the following:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/0005.clip_5F00_image003_5F00_1518A384.jpg"&gt;&lt;img title="clip_image003" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="clip_image003" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/5228.clip_5F00_image003_5F00_thumb_5F00_25B09E72.jpg" width="486" height="235" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The number of configured recovery actions is actually four, the first three being &amp;quot;Restart the service&amp;quot; and the fourth being &amp;quot;Do nothing&amp;quot;, this results in the behavior described above.&lt;/p&gt;  &lt;p&gt;The Windows Service Control Manager UI is limited to displaying only the first 3 actions and therefore gives the wrong impression of the configured actions.&lt;/p&gt;  &lt;p&gt;If you have good reasons to configure the service to restart for subsequent failures you can do so by running the following command at an elevated command prompt:&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Sc.exe failure fwsrv reset= 86400 actions= restart/60000/restart/60000/restart/60000&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;This configures 3 restart actions to restart the service after 60 seconds. The last action will be used to determine the behavior of subsequent crashes.&lt;/p&gt;  &lt;p&gt;To revert to the default TMG behavior please run the following command from an elevated command prompt:-&lt;/p&gt;  &lt;p&gt;&lt;i&gt;Sc.exe failure fwsrv reset= 86400 actions= restart/60000/restart/60000/restart/60000//&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;This will re-configure Service Control Manager to restart the Firewall service for the first 3 crashes but to then take no action for the 4&lt;sup&gt;th&lt;/sup&gt; and subsequent crashes.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Author: &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Gianni Bragante &lt;/p&gt;  &lt;p&gt;Support Engineer - Microsoft Forefront Edge Security Team&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Reviewer: &lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Ian Parramore&lt;/p&gt;  &lt;p&gt;Sr. Escalation Engineer - Microsoft Forefront Edge Security Team&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3577801" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="TMG" scheme="http://blogs.technet.com/b/isablog/archive/tags/TMG/" /><category term="crash" scheme="http://blogs.technet.com/b/isablog/archive/tags/crash/" /></entry><entry><title>Error 64 “ The specified network name is no longer available” while accessing a HTTPS site through ISA 2006</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/05/29/error-64-the-specified-network-name-is-no-longer-available-while-accessing-a-https-site-through-isa-2006.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/05/29/error-64-the-specified-network-name-is-no-longer-available-while-accessing-a-https-site-through-isa-2006.aspx</id><published>2013-05-29T19:33:19Z</published><updated>2013-05-29T19:33:19Z</updated><content type="html">&lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Here’s some info on an interesting support issue I worked the other day. If you happen to    &lt;br /&gt;run into this one day, maybe this will help you get it resolved.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;u&gt;Issue:&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We have a website published through ISA 2006. The site is configured for both HTTP and HTTPS access from the ISA server. When a user connects to the site over HTTP, the site comes up fine.&lt;/p&gt;  &lt;p&gt;But when he tries over HTTPS, he gets a ‘page cannot be displayed’.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;u&gt;Troubleshooting and Resolution: &lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;We started with live logging on the ISA console while doing a repro of the issue. We were seeing ‘Failed Connection Attempts’ for the traffic coming from the test machine used for the repro, with the error message: Error 64 “The specified network name is no longer available”&lt;/p&gt;  &lt;p&gt;This error is very generic and there can be multiple reasons which would translate to this error code.The most common one is when the backend server is performing a dirty TCP connection reset.&lt;/p&gt;  &lt;p&gt;So, to check this further, we collected a network monitor trace on the internal NIC of ISA server.&lt;/p&gt;  &lt;p&gt;We filtered down to the traffic that is of interest to us.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/8306.clip_5F00_image001_5F00_3C50103D.jpg"&gt;&lt;img title="clip_image001" style="display: inline; background-image: none;" border="0" alt="clip_image001" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1882.clip_5F00_image001_5F00_thumb_5F00_277E17BD.jpg" width="451" height="84" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/7776.clip_5F00_image0015_5F00_5493048B.jpg"&gt;&lt;img title="clip_image001[5]" style="display: inline; background-image: none;" border="0" alt="clip_image001[5]" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/0777.clip_5F00_image0015_5F00_thumb_5F00_4C2F2F34.jpg" width="455" height="232" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;So this clearly indicates that the backend server is Resetting the TCP connection prematurely and this is triggering the ‘64 Error’.&lt;/p&gt;  &lt;p&gt;Investigating further, we identified that the backend device is a 3&lt;sup&gt;rd&lt;/sup&gt; party load balancer. And for some unknown reasons, the ISA server was failing at the SSL handshake stage.&lt;/p&gt;  &lt;p&gt;So, we had the 3&lt;sup&gt;rd&lt;/sup&gt; party support team collect a dump of the SSL settings on the Load Balancer and identified the following:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/8228.clip_5F00_image004_5F00_6B05A312.jpg"&gt;&lt;img title="clip_image004" style="display: inline; background-image: none;" border="0" alt="clip_image004" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/6180.clip_5F00_image004_5F00_thumb_5F00_5C5AF72D.jpg" width="360" height="253" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Then, we went back to the Network Monitor trace (the earlier screenshot) and compared this with the ciphers advertised by ISA server in the client hello. RSA_WITH_RC4_128_MD5 is not part of the Cipher list sent by the ISA server.&lt;/p&gt;  &lt;p&gt;Due to this, the 2 peers are not able to successfully choose a common encryption scheme and the SSL handshake fails.&lt;/p&gt;  &lt;p&gt;After identifying this, we had the 3&lt;sup&gt;rd&lt;/sup&gt; party vendor enable additional Ciphers which are accepted by ISA server. &lt;/p&gt;  &lt;p&gt;Once we did this, the published site was accessible from the internet. &lt;/p&gt;  &lt;p&gt;The issue was resolved!!&lt;/p&gt;  &lt;p&gt;Hope this would be helpful when you are troubleshooting website accessibility issues through ISA server…especially with 3&lt;sup&gt;rd&lt;/sup&gt; party load balancers in the infrastructure.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Author:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Karthik Divakaran&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Security Support Engineer - Microsoft Forefront Edge Team&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Reviewers:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Suraj Singh&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Security Support Escalation Engineer - Microsoft Forefront Edge Team&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Richard Barker&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Security Sr. Support Escalation Engineer – Microsoft Forefront Edge Team&lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3575536" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>KB: A recurring monthly report job does not run when expected on an array in Forefront Threat Management Gateway 2010</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/04/16/kb-a-recurring-monthly-report-job-does-not-run-when-expected-on-an-array-in-forefront-threat-management-gateway-2010.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/04/16/kb-a-recurring-monthly-report-job-does-not-run-when-expected-on-an-array-in-forefront-threat-management-gateway-2010.aspx</id><published>2013-04-16T16:09:42Z</published><updated>2013-04-16T16:09:42Z</updated><content type="html">&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/2830886"&gt;&lt;img title="e" border="0" alt="e" align="left" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-69-06-metablogapi/7701.e_5F00_39D5FB59.jpg" width="85" height="84" /&gt;&lt;/a&gt;Just wanted to let you know about a new KB article we published today. This one is a TMG article that talks about an issue where a recurring monthly report job is not created when you expect it.&lt;/p&gt;  &lt;p&gt;You can find the complete article here:&lt;/p&gt;  &lt;p&gt;KB2830886 - A recurring monthly report job does not run when expected on an array in Forefront Threat Management Gateway 2010 (&lt;a href="http://support.microsoft.com/kb/2830886"&gt;http://support.microsoft.com/kb/2830886&lt;/a&gt;)&lt;/p&gt;  &lt;p&gt;&lt;b&gt;J.C. Hornbeck&lt;/b&gt; &lt;strong&gt;| Knowledge Engineer | Microsoft GBS Management and Security Division&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#c0504d"&gt;Get the latest System Center news on&lt;/font&gt; &lt;/b&gt;&lt;a href="https://www.facebook.com/pages/Microsoft-System-Center-Support/111513322193410"&gt;&lt;b&gt;Facebook&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;font color="#c0504d"&gt;and&lt;/font&gt; &lt;/b&gt;&lt;a href="https://twitter.com/#!/MS_SystemCenter"&gt;&lt;b&gt;Twitter&lt;/b&gt;&lt;/a&gt;&lt;b&gt;:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.facebook.com/pages/Microsoft-System-Center-Support/111513322193410"&gt;&lt;img title="clip_image001" border="0" alt="clip_image001" src="http://blogs.technet.com/blogfiles/medv/WindowsLiveWriter/MEDVPrintingOptionsandIssuesyoumayencoun_8540/clip_image001_64a4101d-1898-43ad-8493-b15123a8f037.gif" width="89" height="21" /&gt;&lt;/a&gt; &lt;a href="http://www.twitter.com/MS_SystemCenter"&gt;&lt;img title="clip_image002" border="0" alt="clip_image002" src="http://blogs.technet.com/blogfiles/medv/WindowsLiveWriter/MEDVPrintingOptionsandIssuesyoumayencoun_8540/clip_image002_e463ef66-6372-4614-ad1b-a2e20e16de5f.gif" width="89" height="21" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;System Center All Up: &lt;a href="http://blogs.technet.com/b/systemcenter/"&gt;http://blogs.technet.com/b/systemcenter/&lt;/a&gt;     &lt;br /&gt;System Center – Configuration Manager Support Team blog: &lt;a href="http://blogs.technet.com/configurationmgr/"&gt;http://blogs.technet.com/configurationmgr/&lt;/a&gt;     &lt;br /&gt;System Center – Data Protection Manager Team blog: &lt;a href="http://blogs.technet.com/dpm/"&gt;http://blogs.technet.com/dpm/&lt;/a&gt;     &lt;br /&gt;System Center – Orchestrator Support Team blog: &lt;a href="http://blogs.technet.com/b/orchestrator/"&gt;http://blogs.technet.com/b/orchestrator/&lt;/a&gt;     &lt;br /&gt;System Center – Operations Manager Team blog: &lt;a href="http://blogs.technet.com/momteam/"&gt;http://blogs.technet.com/momteam/&lt;/a&gt;     &lt;br /&gt;System Center – Service Manager Team blog: &lt;a href="http://blogs.technet.com/b/servicemanager"&gt;http://blogs.technet.com/b/servicemanager&lt;/a&gt;     &lt;br /&gt;System Center – Virtual Machine Manager Team blog: &lt;a href="http://blogs.technet.com/scvmm"&gt;http://blogs.technet.com/scvmm&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Windows Intune: &lt;a href="http://blogs.technet.com/b/windowsintune/"&gt;http://blogs.technet.com/b/windowsintune/&lt;/a&gt;     &lt;br /&gt;WSUS Support Team blog: &lt;a href="http://blogs.technet.com/sus/"&gt;http://blogs.technet.com/sus/&lt;/a&gt;     &lt;br /&gt;The AD RMS blog: &lt;a href="http://blogs.technet.com/b/rmssupp/"&gt;http://blogs.technet.com/b/rmssupp/&lt;/a&gt; &lt;/p&gt;  App-V Team blog: &lt;a href="http://blogs.technet.com/appv/"&gt;http://blogs.technet.com/appv/&lt;/a&gt;   &lt;br /&gt;MED-V Team blog: &lt;a href="http://blogs.technet.com/medv/"&gt;http://blogs.technet.com/medv/&lt;/a&gt;   &lt;br /&gt;Server App-V Team blog: &lt;a href="http://blogs.technet.com/b/serverappv"&gt;http://blogs.technet.com/b/serverappv&lt;/a&gt;   &lt;p&gt;The Forefront Endpoint Protection blog : &lt;a href="http://blogs.technet.com/b/clientsecurity/"&gt;http://blogs.technet.com/b/clientsecurity/&lt;/a&gt;     &lt;br /&gt;The Forefront Identity Manager blog : &lt;a href="http://blogs.msdn.com/b/ms-identity-support/"&gt;http://blogs.msdn.com/b/ms-identity-support/&lt;/a&gt;     &lt;br /&gt;The Forefront TMG blog: &lt;a href="http://blogs.technet.com/b/isablog/"&gt;http://blogs.technet.com/b/isablog/&lt;/a&gt;     &lt;br /&gt;The Forefront UAG blog: &lt;a href="http://blogs.technet.com/b/edgeaccessblog/"&gt;http://blogs.technet.com/b/edgeaccessblog/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3567096" width="1" height="1"&gt;</content><author><name>J.C. Hornbeck</name><uri>http://blogs.technet.com/jchornbe/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Forefront Unified Access Gateway 2010 Service Pack 3 Rollup 1 is available for download</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/04/15/forefront-unified-access-gateway-2010-service-pack-3-rollup-1-is-available-for-download.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/04/15/forefront-unified-access-gateway-2010-service-pack-3-rollup-1-is-available-for-download.aspx</id><published>2013-04-15T16:26:43Z</published><updated>2013-04-15T16:26:43Z</updated><content type="html">&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/2827350"&gt;&lt;img title="download" style="border: 0px currentcolor; float: left; display: inline; background-image: none;" border="0" alt="download" align="left" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1234.download_5F00_23F5E79E.jpg" width="85" height="69" /&gt;&lt;/a&gt;We are happy to announce that&lt;b&gt; Rollup 1 for Forefront UAG 2010 Service Pack 3&lt;/b&gt; has been released.&lt;/p&gt;  &lt;p&gt;UAG 2010 Service Pack 3 Rollup 1 is available as a &lt;a href="http://support.microsoft.com/hotfix/KBHotfix.aspx?kbnum=2827350&amp;amp;kbln=en-us"&gt;hotfix download&lt;/a&gt; from Microsoft Support as an update to &lt;a href="http://support.microsoft.com/kb/2744025"&gt;UAG 2010 Service Pack 3&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt; This important update contains 8 new fixes for reported issues as well as enhanced context tracing to more easily filter trace data per session.&lt;/p&gt;  &lt;p&gt;For details, please visit &lt;a href="http://support.microsoft.com/kb/2827350"&gt;KB 2827350: Description of Rollup 1 for Forefront Unified Access Gateway 2010 Service Pack 3&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Please download the Forefront Unified Access Gateway (UAG) 2010 Service Pack 3 package now, and learn more about UAG 2010 SP3 by visiting our &lt;a href="http://go.microsoft.com/fwlink/?LinkId=282423"&gt;TechNet Library&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;J.C. Hornbeck&lt;/b&gt; &lt;strong&gt;| Knowledge Engineer | Microsoft GBS Management and Security Division&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font color="#c0504d"&gt;Get the latest System Center news on&lt;/font&gt; &lt;/b&gt;&lt;a href="https://www.facebook.com/pages/Microsoft-System-Center-Support/111513322193410"&gt;&lt;b&gt;Facebook&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;font color="#c0504d"&gt;and&lt;/font&gt; &lt;/b&gt;&lt;a href="https://twitter.com/#!/MS_SystemCenter"&gt;&lt;b&gt;Twitter&lt;/b&gt;&lt;/a&gt;&lt;b&gt;:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.facebook.com/pages/Microsoft-System-Center-Support/111513322193410"&gt;&lt;img title="clip_image001" border="0" alt="clip_image001" src="http://blogs.technet.com/blogfiles/medv/WindowsLiveWriter/MEDVPrintingOptionsandIssuesyoumayencoun_8540/clip_image001_64a4101d-1898-43ad-8493-b15123a8f037.gif" width="89" height="21" /&gt;&lt;/a&gt; &lt;a href="http://www.twitter.com/MS_SystemCenter"&gt;&lt;img title="clip_image002" border="0" alt="clip_image002" src="http://blogs.technet.com/blogfiles/medv/WindowsLiveWriter/MEDVPrintingOptionsandIssuesyoumayencoun_8540/clip_image002_e463ef66-6372-4614-ad1b-a2e20e16de5f.gif" width="89" height="21" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;System Center All Up: &lt;a href="http://blogs.technet.com/b/systemcenter/"&gt;http://blogs.technet.com/b/systemcenter/&lt;/a&gt;     &lt;br /&gt;System Center – Configuration Manager Support Team blog: &lt;a href="http://blogs.technet.com/configurationmgr/"&gt;http://blogs.technet.com/configurationmgr/&lt;/a&gt;     &lt;br /&gt;System Center – Data Protection Manager Team blog: &lt;a href="http://blogs.technet.com/dpm/"&gt;http://blogs.technet.com/dpm/&lt;/a&gt;     &lt;br /&gt;System Center – Orchestrator Support Team blog: &lt;a href="http://blogs.technet.com/b/orchestrator/"&gt;http://blogs.technet.com/b/orchestrator/&lt;/a&gt;     &lt;br /&gt;System Center – Operations Manager Team blog: &lt;a href="http://blogs.technet.com/momteam/"&gt;http://blogs.technet.com/momteam/&lt;/a&gt;     &lt;br /&gt;System Center – Service Manager Team blog: &lt;a href="http://blogs.technet.com/b/servicemanager"&gt;http://blogs.technet.com/b/servicemanager&lt;/a&gt;     &lt;br /&gt;System Center – Virtual Machine Manager Team blog: &lt;a href="http://blogs.technet.com/scvmm"&gt;http://blogs.technet.com/scvmm&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Windows Intune: &lt;a href="http://blogs.technet.com/b/windowsintune/"&gt;http://blogs.technet.com/b/windowsintune/&lt;/a&gt;     &lt;br /&gt;WSUS Support Team blog: &lt;a href="http://blogs.technet.com/sus/"&gt;http://blogs.technet.com/sus/&lt;/a&gt;     &lt;br /&gt;The AD RMS blog: &lt;a href="http://blogs.technet.com/b/rmssupp/"&gt;http://blogs.technet.com/b/rmssupp/&lt;/a&gt; &lt;/p&gt; App-V Team blog: &lt;a href="http://blogs.technet.com/appv/"&gt;http://blogs.technet.com/appv/&lt;/a&gt;   &lt;br /&gt;MED-V Team blog: &lt;a href="http://blogs.technet.com/medv/"&gt;http://blogs.technet.com/medv/&lt;/a&gt;   &lt;br /&gt;Server App-V Team blog: &lt;a href="http://blogs.technet.com/b/serverappv"&gt;http://blogs.technet.com/b/serverappv&lt;/a&gt;   &lt;p&gt;The Forefront Endpoint Protection blog : &lt;a href="http://blogs.technet.com/b/clientsecurity/"&gt;http://blogs.technet.com/b/clientsecurity/&lt;/a&gt;     &lt;br /&gt;The Forefront Identity Manager blog : &lt;a href="http://blogs.msdn.com/b/ms-identity-support/"&gt;http://blogs.msdn.com/b/ms-identity-support/&lt;/a&gt;     &lt;br /&gt;The Forefront TMG blog: &lt;a href="http://blogs.technet.com/b/isablog/"&gt;http://blogs.technet.com/b/isablog/&lt;/a&gt;     &lt;br /&gt;The Forefront UAG blog: &lt;a href="http://blogs.technet.com/b/edgeaccessblog/"&gt;http://blogs.technet.com/b/edgeaccessblog/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3566873" width="1" height="1"&gt;</content><author><name>J.C. Hornbeck</name><uri>http://blogs.technet.com/jchornbe/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>TMG stopped processing web proxy requests</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/04/09/tmg-stopped-processing-web-proxy-requests.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/04/09/tmg-stopped-processing-web-proxy-requests.aspx</id><published>2013-04-09T14:16:24Z</published><updated>2013-04-09T14:16:24Z</updated><content type="html">&lt;p&gt;This post is about an issue I worked on several days ago.&lt;/p&gt;  &lt;p&gt;Symptom:&lt;/p&gt;  &lt;p&gt;========&lt;/p&gt;  &lt;p&gt;My customer had a TMG array with two nodes running with NLB. The problem they faced was that from time to time some TMG node couldn't process traffic anymore: requests to the virtual IP (VIP) failed and only rebooting the TMG machine eliminated the issue.&lt;/p&gt;  &lt;p&gt;IE was configured to use the NLB virtual IP (VIP) as proxy address. When the issue happened users couldn’t browse internet pages -&amp;#160; the browser didn't show any error page, it just stayed with a blank page. &lt;/p&gt;  &lt;p&gt;Troubleshooting:&lt;/p&gt;  &lt;p&gt;=============&lt;/p&gt;  &lt;p&gt;First of all, I looked at the TMG Web proxy log and found an&amp;#160; error logged there with the result code of 11001 (WSAHOST_NOT_FOUND) for&amp;#160; the request for&amp;#160; “contoso.com”, which we tried to browse in order to reproduce the issue.&lt;/p&gt;  &lt;p&gt;Then I took a look at a captured network monitor trace in order to find an appropriate network conversation between the client and TMG:&lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160;&amp;#160; Time&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Delta time&amp;#160;&amp;#160;&amp;#160;&amp;#160; Source&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Destination&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Protocol Length&amp;#160;&amp;#160; Info&lt;/p&gt;  &lt;p&gt;…&lt;/p&gt;  &lt;p&gt;11:07:26.566261000&amp;#160; 1.376436000&amp;#160;&amp;#160;&amp;#160; CLIENT_IP&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; TMG_VIP&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; HTTP&amp;#160;&amp;#160;&amp;#160;&amp;#160; 433&amp;#160;&amp;#160;&amp;#160; GET &lt;a href="http://contoso.com/"&gt;http://contoso.com/&lt;/a&gt; HTTP/1.1 &lt;/p&gt;  &lt;p&gt;11:07:26.570933000&amp;#160; 0.004672000&amp;#160;&amp;#160;&amp;#160; TMG_VIP&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; CLIENT_IP&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; HTTP&amp;#160;&amp;#160;&amp;#160;&amp;#160; 1440&amp;#160;&amp;#160; HTTP/1.1 502 Proxy Error ( The host was not found. )&amp;#160; (text/html)&lt;/p&gt;  &lt;p&gt;…&lt;/p&gt;  &lt;p&gt;In a web proxy scenario, the web proxy is supposed to resolve the name, however, by some reason the node didn't manage to resolve the remote host.&lt;/p&gt;  &lt;p&gt;As the next step, I filtered out the trace for DNS traffic and didn't find DNS packets on the node at all – this looked very suspicious.&lt;/p&gt;  &lt;p&gt;Therefore I looked at Netstat and its output showed around ~62000 lines similar to the followings, whereas 2580 was the pid of wspsrv.exe: &lt;/p&gt;  &lt;p&gt;…&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4002&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4003&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4004&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4005&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4006&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4007&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4020&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4021&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4022&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4023&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4024&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4025&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;&amp;#160; UDP&amp;#160;&amp;#160;&amp;#160; 0.0.0.0:4026&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; *:*&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 2580&lt;/p&gt;  &lt;p&gt;…&lt;/p&gt;  &lt;p&gt;So TMG seemed to use up all UDP ports – hence there was no free UDP port left to use as source port for dns queries. This explained why name resolution failed and why TMG returned 502. &lt;/p&gt;  &lt;p&gt;Why was such a great amount of ports used by TMG?&lt;/p&gt;  &lt;p&gt;My guess was that it might be doing it on behalf of a client. Therefore, I looked at the Firewall log which showed that there were huge amount of UDP requests from a single client to different external hosts.&lt;/p&gt;  &lt;p&gt;Luckily TMG firewall client was installed on the client machine which gave us an application name:&lt;/p&gt;  &lt;p&gt;…&lt;/p&gt;  &lt;p&gt;7:27:51 Establish CLINET2_IP 2058 EXTERNAL_HOST_1 54150 0x0 Access Internet UDP domain\user &lt;i&gt;smax4pnp&lt;/i&gt;.exe:3:5.1 TMG1 Unidentified IP Traffic&lt;/p&gt;  &lt;p&gt;7:27:52 Establish CLINET2_IP 2033 EXTERNAL_HOST_2 9362 0x0 Access Internet UDP domain\user &lt;i&gt;smax4pnp&lt;/i&gt;.exe:3:5.1 TMG1 Unidentified IP Traffic&lt;/p&gt;  &lt;p&gt;7:27:53 Terminate CLINET2_IP 2026 EXTERNAL_HOST_3 59866 0x80074e20 Access Internet UDP domain\user &lt;i&gt;smax4pnp&lt;/i&gt;.exe:3:5.1 TMG1 Unidentified IP Traffic&lt;/p&gt;  &lt;p&gt;… &lt;/p&gt;  &lt;p&gt;So TMG used up all the available ports due to the excessive amount of request from this&amp;#160; client/application.&lt;/p&gt;  &lt;p&gt;In order to resolve the issue the customer disabled the client&amp;#160; that has&amp;#160; been causing this huge UDP traffic.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Author: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Vasily Kobylin, Senior Support Engineer, EMEA Forefront Edge Team&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Reviewer:&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;Balint Toth, Senior Support Escalation Engineer, EMEA Forefront Edge Team&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3564332" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="TMG" scheme="http://blogs.technet.com/b/isablog/archive/tags/TMG/" /></entry><entry><title>How to configure the TMG Service Account to avoid problem with logging on SQL Server</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/04/02/how-to-configure-the-tmg-service-account-to-avoid-problem-with-logging-on-sql-server.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/04/02/how-to-configure-the-tmg-service-account-to-avoid-problem-with-logging-on-sql-server.aspx</id><published>2013-04-02T11:26:56Z</published><updated>2013-04-02T11:26:56Z</updated><content type="html">&lt;p&gt;One of the features introduced with TMG Service Pack 2 is to run the Firewall Service with a Domain account, this allow users to authenticate with Kerberos when using NLB.   &lt;br /&gt;Find more information about this feature here: &lt;a href="http://technet.microsoft.com/en-us/library/hh454304.aspx"&gt;http://technet.microsoft.com/en-us/library/hh454304.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;However you should pay attention when specifying the account name to avoid problems with logging to SQL Server, either local or remote.&lt;/p&gt;  &lt;p&gt;The account specified is used by TMG to configure the service and also to create the Login in SQL Server.   &lt;br /&gt;For the TMG Firewall service to start any format is fine, but for SQL Server only the format domainName\loginName is valid.&lt;/p&gt;  &lt;p&gt;For example if you want to use the account TMGSvc in the domain CONTOSO you have to enter CONTOSO\TMGSvc.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/6518.clip_5F00_image001_5F00_6A38A616.png"&gt;&lt;img title="clip_image001" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="clip_image001" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/2248.clip_5F00_image001_5F00_thumb_5F00_1AEBADC2.png" width="271" height="356" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Using the UPN (User Principal Name) format or the FQDN (Fully Qualified Domain Name) does not work.   &lt;br /&gt;For example you cannot use &lt;a href="mailto:TMGSvc@Contoso.com"&gt;TMGSvc@Contoso.com&lt;/a&gt; or Contoso.com\TMGSvc&lt;/p&gt;  &lt;p&gt;The SQL Server documentation for the &lt;a href="http://technet.microsoft.com/en-us/library/ms189751(v=sql.105).aspx"&gt;CREATE LOGIN&lt;/a&gt; command has the following note:&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&amp;quot;When you are creating logins that are mapped from a Windows domain account, you must use the pre-Windows 2000 user logon name in the format [&amp;lt;domainName&amp;gt;\&amp;lt;loginName&amp;gt;].&amp;quot;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;If you try using an invalid format you will see the Log Status as Disconnected and your LLQ folder growing:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/8228.clip_5F00_image002_5F00_121BA576.png"&gt;&lt;img title="clip_image002" style="border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px" border="0" alt="clip_image002" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/2046.clip_5F00_image002_5F00_thumb_5F00_6A08F656.png" width="380" height="310" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Author:      &lt;br /&gt;&lt;/strong&gt;Gianni Bragante     &lt;br /&gt;Support Engineer - Microsoft Forefront Edge Security Team&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Reviewer:      &lt;br /&gt;&lt;/strong&gt;Lars Bentzen     &lt;br /&gt;Sr. Escalation Engineer - Microsoft Forefront Edge Security Team&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3562640" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="TMG" scheme="http://blogs.technet.com/b/isablog/archive/tags/TMG/" /><category term="Logging" scheme="http://blogs.technet.com/b/isablog/archive/tags/Logging/" /><category term="sql" scheme="http://blogs.technet.com/b/isablog/archive/tags/sql/" /></entry><entry><title>Clients Are Not Prompted to Choose a Certificate When Authenticating to ISA/TMG</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/03/06/clients-are-not-prompted-to-choose-a-certificate-when-authenticating-to-isa-tmg.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/03/06/clients-are-not-prompted-to-choose-a-certificate-when-authenticating-to-isa-tmg.aspx</id><published>2013-03-06T15:14:30Z</published><updated>2013-03-06T15:14:30Z</updated><content type="html">&lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;Recently I have been seeing an increasing number of cases with the same symptom especially in the military and the government sector and even in contractors for the government. In these highly secure environments clients largely rely on the use of a “smart” card known as Common Access Cards (CAC) for authentication to their various types of servers and services.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Symptom&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Your Internet Security and Acceleration Server (ISA) or Forefront Threat Management Gateway 2010 (TMG) Server is publishing resources internally/externally and your Web Listener is configure to use SSL Client Certificate Authentication. When clients navigate to the site that is published they would normally be prompted to choose their client certificate. Some or all of the clients are not being prompted to choose the certificate. On the ISA/TMG server, you may see a Warning in your Event Log with an Event ID of 36885.&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Event Type: Warning &lt;/em&gt;&lt;i&gt;     &lt;br /&gt;&lt;em&gt;Event Source: Schannel &lt;/em&gt;      &lt;br /&gt;&lt;em&gt;Event Category: None &lt;/em&gt;      &lt;br /&gt;&lt;em&gt;Event ID: 36885 &lt;/em&gt;      &lt;br /&gt;&lt;em&gt;Date: date&lt;/em&gt;       &lt;br /&gt;&lt;em&gt;Time: time&lt;/em&gt;       &lt;br /&gt;&lt;em&gt;User: &lt;/em&gt;      &lt;br /&gt;&lt;em&gt;Computer: COMPUTERNAME&lt;/em&gt;       &lt;br /&gt;&lt;em&gt;Description: When asking for client authentication, this server sends a list of trusted certificate authorities to the client. The client uses this list to choose a client certificate that is trusted by the server. Currently, this server trusts so many certificate authorities that the list has grown too long. This list has thus been truncated. The administrator of this machine should review the certificate authorities trusted for client authentication and remove those that do not really need to be trusted.&lt;/em&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;This issue is caused when there are too many trusted certificate authorities in the Certificate Store on ISA/TMG. This is particularly common for servers that need a long list of Department of Defense (DoD) Certificate Authorities. When the list grows beyond 12,228 bytes (the maximum size the current Schannel security package supports) the list will be truncated. If the client doesn't receive the root CA that it needs because it has been truncated, it will not prompt to choose the certificate.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Resolution&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;There are a few workarounds for this but the one that is easiest to implement and seems to fit the needs of most organizations is below.&lt;/p&gt;  &lt;p&gt;On the server or servers that are running ISA/TMG you will need to set the following registry entry to 0 (false):&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Value name: SendTrustedIssuerList&lt;/strong&gt;&lt;b&gt;      &lt;br /&gt;&lt;strong&gt;Value type: REG_DWORD&lt;/strong&gt;       &lt;br /&gt;&lt;strong&gt;Value data: 0&lt;/strong&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;By default the value is 1 (true).&lt;/p&gt;  &lt;p&gt;For other possible workarounds please see this KB:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/933430"&gt;http://support.microsoft.com/kb/933430&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Conclusion&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Troubleshooting SSL Client Certificate issues can be tricky and time consuming. This issue was certainly difficult to identify the first time I saw it. Hopefully the information I have given you here can save you time, money, and aggravation.&lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Author:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Keith Abluton:&lt;/p&gt;  &lt;p&gt;Security Support Escalation Engineer - MSD Security Team&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Reviewer:&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Richard Barker&lt;/p&gt;  &lt;p&gt;Sr. Security Support Escalation Engineer - MSD Security Team&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3556811" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>Access to remote FTP server through TMG 2010 may fail with error 550 (Access Denied)</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/03/05/access-to-remote-ftp-server-through-tmg-2010-may-fail-with-error-550-access-denied.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/03/05/access-to-remote-ftp-server-through-tmg-2010-may-fail-with-error-550-access-denied.aspx</id><published>2013-03-05T10:00:00Z</published><updated>2013-03-05T10:00:00Z</updated><content type="html">&lt;p&gt;Hi everybody!&lt;/p&gt;
&lt;p&gt;In this article we will see how to troubleshoot an issue with accessing an FTP server behind TMG 2010.&lt;/p&gt;
&lt;p&gt;Imagine we have the following situation: a client PC on an internal corporate network want to access a remote FTP server through TMG 2010 using an FTP client such as,&amp;nbsp;for example,&amp;nbsp;&lt;strong&gt;&lt;em&gt;FileZilla&lt;/em&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/3566.clip_5F00_image0027_5F00_1F82ED58.png"&gt;&lt;img style="background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;" title="clip_image002[7]" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/6204.clip_5F00_image0027_5F00_thumb_5F00_5755317B.png" alt="clip_image002[7]" width="428" height="326" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The way the FTP is configured (authentication, encryption, ecc&amp;hellip;) is out of interest for this case.&lt;/p&gt;
&lt;p&gt;On the TMG server, we&amp;rsquo;ve created an &lt;em&gt;access rule&lt;/em&gt; allowing &amp;ldquo;&lt;em&gt;Read-Only&lt;/em&gt;&amp;rdquo; outbound requests for the&amp;nbsp;FTP protocol:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/0334.clip_5F00_image004_5F00_15DA7F22.jpg"&gt;&lt;img style="background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;" title="clip_image004" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/4544.clip_5F00_image004_5F00_thumb_5F00_49A27573.jpg" alt="clip_image004" width="550" height="211" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/4048.clip_5F00_image006_5F00_336C5A21.jpg"&gt;&lt;img style="background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;" title="clip_image006" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/6201.clip_5F00_image006_5F00_thumb_5F00_797D1734.jpg" alt="clip_image006" width="258" height="286" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;When we try to connect to our remote FTP server using,&amp;nbsp;for example,&amp;nbsp;&lt;em&gt;FileZilla,&lt;/em&gt; we may face the following error:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/3652.clip_5F00_image008_5F00_2D450D86.jpg"&gt;&lt;img style="background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;" title="clip_image008" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/2860.clip_5F00_image008_5F00_thumb_5F00_6FD4A8FE.jpg" alt="clip_image008" width="630" height="395" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;FTP connection issues through ISA/TMG could be related to many different aspects.&lt;/p&gt;
&lt;p&gt;In the following article it&amp;rsquo;s possible to find a resolution for many of the most common problems:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://technet.microsoft.com/en-us/library/bb794745.aspx"&gt;http://technet.microsoft.com/en-us/library/bb794745.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The problem we&amp;rsquo;re focusing on in this article, however, is not included in the above troubleshooting guide and depends on a specific by-design behavior of TMG server.&lt;/p&gt;
&lt;p&gt;Basically, in our case we see that the connection attempt is failing due to a &amp;ldquo;&lt;strong&gt;550-Access Denied&lt;/strong&gt;&amp;rdquo; error after having performed a &lt;strong&gt;MLSD&lt;/strong&gt; command.&lt;/p&gt;
&lt;p&gt;What is &lt;strong&gt;MLSD &lt;/strong&gt;exactly ?&lt;/p&gt;
&lt;p&gt;Here we can find a description of what MLSD is used for:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://tools.ietf.org/html/draft-ietf-ftpext-mlst-16#section-7"&gt;http://tools.ietf.org/html/draft-ietf-ftpext-mlst-16#section-7&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As we can see from the above:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The MLST and MLSD commands are intended to standardize the file and directory information returned by the Server-FTP process. These commands differ from the LIST command in that the format of the replies is strictly defined although extensible.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;In the default configuration of the TMG FTP Access filter in &amp;ldquo;Read-Only Mode&amp;rdquo;, the filter will only allow a specific subset of FTP commands. The &lt;strong&gt;MLSD&lt;/strong&gt; command is not included in this set of &amp;ldquo;&lt;em&gt;Read-Only&lt;/em&gt;&amp;rdquo; commands. FTP clients using LIST command will not experience this problem, since LIST is&amp;nbsp;an &lt;em&gt;allowed &lt;/em&gt;command.&lt;/p&gt;
&lt;p&gt;Its easy to resolve the problem by allowing &lt;em&gt;write-permissions&lt;/em&gt; in the FTP-Filter advanced properties of our access rule:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/4201.clip_5F00_image010_5F00_350D0028.jpg"&gt;&lt;img style="background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;" title="clip_image010" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/0407.clip_5F00_image010_5F00_thumb_5F00_14198D81.jpg" alt="clip_image010" width="279" height="311" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Now, granting &lt;em&gt;write rights&lt;/em&gt; is not always a good choice, and most of the times this is not allowed nor suggested.&lt;/p&gt;
&lt;p&gt;Nevertheless, a workaround exists for this situation: in fact, it&amp;rsquo;s possible to add the &lt;strong&gt;MLDS&lt;/strong&gt; command in the &amp;ldquo;&lt;em&gt;allowed-commands&lt;/em&gt; &lt;em&gt;list&lt;/em&gt;&amp;rdquo; of the &amp;ldquo;&lt;em&gt;Read-only&lt;/em&gt;&amp;rdquo; TMG FTP filter.&lt;/p&gt;
&lt;p&gt;The following MSDN article explains how to configure add-ins:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/dd435753.aspx"&gt;http://msdn.microsoft.com/en-us/library/dd435753.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Specifically:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;FTP Access Filter&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;FTP Access Filter is an application filter that is installed with Forefront TMG. It enables FTP protocols. When running in read-only mode, FTP Access Filter blocks all commands in the control channel except the following commands: ABOR, ACCT, CDUP, CWD /0, FEAT, HELP, LANG, LIST, MODE, NLST, NOOP, PASS, PASV, PORT, PWD /0, QUIT, REIN, REST, RETR, SITE, STRU, SYST, TYPE, USER, XDUP, XCWD, XPWD, SMNT. This should block any writing to the server side. &lt;span style="text-decoration: underline;"&gt;The default list of allowed commands can be replaced by a customized list that is written to the collection of vendor parameters sets (&lt;strong&gt;FPCVendorParametersSets&lt;/strong&gt;) associated with the filter&lt;/span&gt;. The Firewall service must restarted for the new settings to take effect. &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;The above article provides a script example through which it is possible to customize FTP filter list. This way, it will be possible to keep the filter configured in &lt;em&gt;Read-Only&lt;/em&gt; mode, and also allow the&amp;nbsp;FileZilla connection to&amp;nbsp;work as expected.&lt;/p&gt;
&lt;p&gt;Hope this can be useful!&lt;/p&gt;
&lt;p&gt;Let's see you back with the next topic!!&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Author: &lt;br /&gt;&lt;/em&gt;&lt;em&gt;&lt;strong&gt;Daniele Gaiulli&lt;/strong&gt; &lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Support Engineer &amp;ndash; EMEA Forefront Edge&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Reviewer: &lt;br /&gt;&lt;/em&gt;&lt;em&gt;&lt;strong&gt;Philipp Sand&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Support Escalation Engineer &amp;ndash; EMEA Forefront Edge&lt;/em&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3556471" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author><category term="Troubleshooting" scheme="http://blogs.technet.com/b/isablog/archive/tags/Troubleshooting/" /><category term="TMG" scheme="http://blogs.technet.com/b/isablog/archive/tags/TMG/" /><category term="Threat Management Gateway" scheme="http://blogs.technet.com/b/isablog/archive/tags/Threat+Management+Gateway/" /><category term="Forefront TMG" scheme="http://blogs.technet.com/b/isablog/archive/tags/Forefront+TMG/" /><category term="ftp" scheme="http://blogs.technet.com/b/isablog/archive/tags/ftp/" /></entry><entry><title>You can remotely manage the Enterprise Policy, but not the Array Policy</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/02/08/you-can-remotely-manage-the-enterprise-policy-but-not-the-array-policy.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/02/08/you-can-remotely-manage-the-enterprise-policy-but-not-the-array-policy.aspx</id><published>2013-02-08T15:10:27Z</published><updated>2013-02-08T15:10:27Z</updated><content type="html">&lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;I’ll try to elaborate on the issue using as many illustrations and snapshots as possible. When I came across this issue, it was quite surprising.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;32-bit Remote Management Client&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;In the TMG environment, we are using a single EMS (Enterprise Management Server) with a single Array. There are two TMG nodes joined to this array. To manage the environment we are using a Windows 7 32-bit machine with a &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=14238"&gt;32-bit client&lt;/a&gt;. Please use this &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=14238http://www.microsoft.com/en-us/download/details.aspx?id=14238"&gt;link&lt;/a&gt; download the 32-bit client (&lt;b&gt;TMG_ENU_Management_x86.exe)&lt;/b&gt;. Note that you will need to login with a Microsoft Live Id and register in order to download. &lt;/p&gt;  &lt;p&gt;Once downloaded, install the client and connect to the EMS server using its FQDN. Make sure EMS is configured to allow remote management, refer to the below mentioned articles.&lt;/p&gt;  &lt;p&gt;· About Forefront TMG roles and permissions - &lt;a href="http://technet.microsoft.com/en-us/library/dd897006.aspx#BKMK_RolesAndPermissions"&gt;http://technet.microsoft.com/en-us/library/dd897006.aspx#BKMK_RolesAndPermissions&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;· Configuring roles and permissions - &lt;a href="http://technet.microsoft.com/en-us/library/dd441007.aspx"&gt;http://technet.microsoft.com/en-us/library/dd441007.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The relevant Users on the list should be able to gain access to the TMG EMS server for administration.&lt;/p&gt;  &lt;p&gt;After assigning the correct set of permissions and remote access to TMG EMS server, you can remotely access the Enterprise Policy and make allowed changes.&lt;/p&gt;  &lt;p&gt;But while accessing Array nothing displays, it doesn’t even shows the arrays created in the enterprise. Refer to below mentioned Snips.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1222.clip_5F00_image002_5F00_06EAD753.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/7585.clip_5F00_image002_5F00_thumb_5F00_57B8EBBB.png" width="457" height="317" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Here in this snip we can see that Enterprise policy is displayed.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/8737.clip_5F00_image004_5F00_768F5F99.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image004" border="0" alt="clip_image004" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/3858.clip_5F00_image004_5F00_thumb_5F00_2ECDD6B2.png" width="459" height="317" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Here you can see the focus is on “Arrays”, but no policies are displayed.&lt;/p&gt;  &lt;p&gt;Let’s check and compare the version on TMG EMS server and then on this client.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/6406.clip_5F00_image006_5F00_74DE93C5.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image006" border="0" alt="clip_image006" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/6683.clip_5F00_image006_5F00_thumb_5F00_4618DB23.png" width="303" height="223" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This is the version number from TMG EMS server which is updated to latest i.e. SP2 RU2&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1307.clip_5F00_image008_5F00_4BF37EBC.png"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image008" border="0" alt="clip_image008" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/7167.clip_5F00_image008_5F00_thumb_5F00_321F488D.png" width="304" height="231" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This is the version number from client which is updated to SP1 UP1.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;The major cause of this is due to version mismatch between the management console and the TMG enterprise. For example the TMG enterprise is at SP2 RollUP2 update level which is build number 7.0.9193.540 and the TMG management console on remote 32bit machine is at RTM which is build number 7.0.7734.100 (refer to the &lt;a href="http://social.technet.microsoft.com/wiki/contents/articles/1995.list-of-build-numbers-for-microsoft-forefront-threat-management-gateway-tmg.aspx"&gt;article&lt;/a&gt;).&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;This can be resolved by updating the TMG RTM management console on 32bit Remote machine. Refer to the links mentioned below to download and install the relevant updates.&lt;/p&gt;  &lt;p&gt;· &lt;a href="https://secure.logmeinrescue-enterprise.com/enterprise/home.aspxhttp:/download.microsoft.com/download/C/5/0/C50C9DD6-AF7F-4338-9816-0DBD43C81F1A/TMG-KB981324-x86-ENU.msp"&gt;SP1&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;· &lt;a href="http://download.microsoft.com/download/B/3/1/B314021A-61D1-4CA2-8752-906E635AF251/TMG-KB2288910-x86-ENU.exe"&gt;SP1 UP1&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;· &lt;a href="http://download.microsoft.com/download/2/2/4/22429B93-13B7-4181-9F24-70A6F5CB3DE8/TMG-KB2555840-x86-ENU.exe"&gt;SP2&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This completely depends on the version level of the TMG environment. Check the article mentioned below for all the relevant TMG versions.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/b/keithab/archive/2011/09/27/forefront-tmg-2010-service-pack-rollup-and-version-number-reference.aspx"&gt;http://blogs.technet.com/b/keithab/archive/2011/09/27/forefront-tmg-2010-service-pack-rollup-and-version-number-reference.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Match the version with the updates to the level TMG EMS server is on. There are no rollups released for the MMC.&lt;/p&gt;  &lt;p&gt;After updating the client to SP2 we were able to access the array policies on the client machine.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size="2"&gt;64-bit Remote Management Client&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Now goes the story for 64-bit setup. Just to mention there is no separate TMG mmc console installation msp available. For this installation, the TMG 2010 ISO/DVD is used.&lt;/p&gt;  &lt;p&gt;NOTE: The following 4 steps outline the default MMC install using the install media.&lt;/p&gt;  &lt;p&gt;You may have followed these steps, believing that you would be able to manage TMG EMS remotely using the MMC.&lt;/p&gt;  &lt;p&gt;1. TMG setup from installation ISO/DVD by starting Preparation Tools first.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/3857.clip_5F00_image010_5F00_633E832D.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image010" border="0" alt="clip_image010" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/2055.clip_5F00_image010_5F00_thumb_5F00_1DB98302.jpg" width="357" height="272" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;2. On Welcome screen accepted the terms for installation.&lt;/p&gt;  &lt;p&gt;3. On Installation type dialog box selected Forefront TMG Management.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/7651.clip_5F00_image012_5F00_1CE11D18.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image012" border="0" alt="clip_image012" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/7144.clip_5F00_image012_5F00_thumb_5F00_2327F3A6.jpg" width="429" height="298" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;4. Wizard finishes its work.&lt;/p&gt;  &lt;p&gt;After a default installation of the MMC (from the install media), you may be surprised to find out it doesn’t work &lt;b&gt;.&lt;/b&gt; Because TMG is at SP2 or above update level and the MMC installation is at RTM level.&lt;/p&gt;  &lt;p&gt;There are updates available which can be used to bring the MMC to the same update level as the TMG EMS server is at. But the procedure used for 32bit installation doesn’t work for 64bit.&lt;/p&gt;  &lt;p&gt;I know there are a lot of questions surfacing, but I have the answer. &lt;/p&gt;  &lt;p&gt;Because the 64bit mmc is installed straight from the install media, we’ll have to update the installation itself to SP2/ relevant to your environment.&lt;/p&gt;  &lt;p&gt;To do this, we’ll need to create a “TMG 2010 Slipstream” installation, in which we update the TMG installation MSI itself.&lt;/p&gt;  &lt;h3&gt;&amp;#160;&lt;/h3&gt;  &lt;h3&gt;&lt;font size="2"&gt;Steps for TMG 2010 Slipstream installation.&lt;/font&gt;&lt;/h3&gt;  &lt;p&gt;1. If the TMG 2010 MMC console was previously installed directly from the install media, you’ll need to uninstall it from Control Panel &amp;gt;&amp;gt; Programs and Feature.&lt;/p&gt;  &lt;p&gt;2. Copy all the contents from TMG 2010 ISO/DVD to a folder on HDD. In this example, we will copy the contents to C:\TMG.&lt;/p&gt;  &lt;p&gt;3. Download the following TMG 2010 updates; making sure you download all 64bit versions. Use the following links:&lt;/p&gt;  &lt;p&gt;a. SP1 - &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=16734"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=16734&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;b. UP1 - &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=11445"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=11445&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;c. SP2 - &lt;a href="http://www.microsoft.com/en-us/download/details.aspx?id=27603"&gt;http://www.microsoft.com/en-us/download/details.aspx?id=27603&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;4. Once you have downloaded all three files, copy the files to C:\TMG\FPC&lt;/p&gt;  &lt;p&gt;5. The UP1 and SP2 are in .exe format, therefore we will need to extract the msp files so they can be used for slipstreaming TMG 2010.&lt;/p&gt;  &lt;p&gt;6. Open a command prompt with elevated privileges and, in the C:\TMG\FPC folder, execute the following commands. &lt;/p&gt;  &lt;p&gt;a. SP1 Update1 - TMG-KB2288910-amd64-ENU.exe /t TMGSP1U1&lt;/p&gt;  &lt;p&gt;b. You’ll get a dialog after completion.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/2867.clip_5F00_image013_5F00_1B305144.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image013" border="0" alt="clip_image013" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/5670.clip_5F00_image013_5F00_thumb_5F00_7389D519.jpg" width="338" height="179" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Click ok to close.&lt;/p&gt;  &lt;p&gt;c. SP2 - TMG-KB2555840-amd64-ENU.exe /t TMGSP2&lt;/p&gt;  &lt;p&gt;d. You’ll get a dialog after completion.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/2437.clip_5F00_image014_5F00_0AD4D98B.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image014" border="0" alt="clip_image014" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1768.clip_5F00_image014_5F00_thumb_5F00_22F843E6.jpg" width="340" height="192" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Click ok to close.&lt;/p&gt;  &lt;p&gt;7. Below is the snip for commands and folders I used.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1362.clip_5F00_image016_5F00_423AEAB9.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image016" border="0" alt="clip_image016" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/3414.clip_5F00_image016_5F00_thumb_5F00_56540742.jpg" width="463" height="235" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;8. Under C:\TMG\FPC, there should be two new folders called TMGSP1UP1 and TMGSP2. Both of these folders will contain the extracted msp file.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/0842.clip_5F00_image018_5F00_1F2A7949.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image018" border="0" alt="clip_image018" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/5141.clip_5F00_image018_5F00_thumb_5F00_3E6D201C.jpg" width="453" height="223" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;9. Copy the msp files to FPC folder.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/3808.clip_5F00_image020_5F00_398A6C60.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image020" border="0" alt="clip_image020" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1854.clip_5F00_image020_5F00_thumb_5F00_43DB90C0.jpg" width="456" height="245" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;10. Now let’s create slipstream for TMG 2010. Follow the commands and make sure you update it to the same level as TMG EMS.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;a. SP1 - msiexec /a ms_fpc_server.msi /p tmg-kb981324-amd64-enu.msp&lt;b&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;This will initiate installation wizard, which will slipstream the TMG2010 installation with SP1&lt;/p&gt;  &lt;p&gt;b. SP1UP1 - msiexec /a MS_FPC_Server.msi /p TMG-KB2288910-amd64-ENU.msp&lt;/p&gt;  &lt;p&gt;This will initiate installation wizard, which will slipstream the TMG2010 installation with SP1UP1.&lt;/p&gt;  &lt;p&gt;c. SP2 - msiexec /a MS_FPC_Server.msi /p TMG-KB2555840-amd64-ENU.msp&lt;/p&gt;  &lt;p&gt;This will initiate installation wizard, which will slipstream the TMG2010 installation with SP2.&lt;/p&gt;  &lt;p&gt;11. Next, you can delete the following highlighted files and folders from C:\TMG\FPC.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/8765.clip_5F00_image022_5F00_77A38711.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image022" border="0" alt="clip_image022" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/7612.clip_5F00_image022_5F00_thumb_5F00_76CB2127.jpg" width="466" height="247" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;12. Once deleted, the C:\TMG\FPC folder appear as follows: &lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/0358.clip_5F00_image024_5F00_27EA5BC8.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image024" border="0" alt="clip_image024" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/8272.clip_5F00_image024_5F00_thumb_5F00_0043DF9E.jpg" width="467" height="135" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;13. Now create an ISO/DVD of the entire C:\TMG folder. Make sure you do not create and ISO/DVD out of only FPC folder.&lt;/p&gt;  &lt;p&gt;14. Now this ISO/DVD can be used to install TMG mmc console on a 64-bit client machine using the steps mentioned below.&lt;/p&gt;  &lt;p&gt;a. Start TMG setup from installation ISO/DVD by starting Preparation Tools first.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/1030.clip_5F00_image025_5F00_666FA96E.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image025" border="0" alt="clip_image025" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/6786.clip_5F00_image025_5F00_thumb_5F00_3EC92D44.jpg" width="377" height="287" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;b. On Welcome screen click next and accept the terms for installation.&lt;/p&gt;  &lt;p&gt;c. On Installation type dialog box select Forefront TMG Management only.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/0830.clip_5F00_image026_5F00_568064AA.jpg"&gt;&lt;img style="background-image: none; border-right-width: 0px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px" title="clip_image026" border="0" alt="clip_image026" src="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-48-31-metablogapi/5224.clip_5F00_image026_5F00_thumb_5F00_23B05E36.jpg" width="381" height="265" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;d. Let wizard to finish its work and then click Finish. This will start mmc installation wizard.&lt;/p&gt;  &lt;p&gt;e. Once installation finishes you can access the array policies as well, provided that appropriate permissions are assigned.&lt;/p&gt;  &lt;p&gt;Thanks for reading through, I hope I was able to clear your doubts and provide a solution. If you are still facing the issue then I would recommend opening a case with Microsoft CSS.&lt;/p&gt;  &lt;p&gt;Author:&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Vivek Kumar Sharma&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Support Engineer – MSD Security Division&lt;/p&gt;  &lt;p&gt;Reviewers:&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Junaid Jan&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;Security Support Escalation Engineer – MSD Security Division&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3551272" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author></entry><entry><title>TMG SP2 Rollup 3 available</title><link rel="alternate" type="text/html" href="http://blogs.technet.com/b/isablog/archive/2013/01/17/tmg-sp2-rollup-3-available.aspx" /><id>http://blogs.technet.com/b/isablog/archive/2013/01/17/tmg-sp2-rollup-3-available.aspx</id><published>2013-01-17T14:14:00Z</published><updated>2013-01-17T14:14:00Z</updated><content type="html">&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;We are happy to announce the availability of Rollup 3 for Forefront Threat Management Gateway (TMG) 2010 Service Pack 2 (SP2). TMG SP2 Rollup 3 is available for download here:&amp;nbsp;&lt;a href="http://support.microsoft.com/kb/2735208"&gt;Rollup 3 for Forefront Threat Management Gateway (TMG) 2010 Service Pack 2&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Please see KB Article ID: 2735208 for details of the fixes included in this rollup.&amp;nbsp;The Build Number for this update is: 7.0.9193.575&lt;/p&gt;
&lt;p&gt;To install this update, you must be running Forefront Threat Management Gateway 2010 Service Pack 2.&lt;/p&gt;
&lt;p&gt;For more information about Forefront Threat Management Gateway 2010 SP2, please see the following Microsoft website:&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=27603"&gt;Download information for Forefront TMG 2010 SP2&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thank you,&lt;/p&gt;
&lt;p&gt;Forefront TMG Team&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3546471" width="1" height="1"&gt;</content><author><name>Forefront TMG Team</name><uri>http://blogs.technet.com/fftmgblog_4000_hotmail.com/ProfileUrlRedirect.ashx</uri></author></entry></feed>