website statistics
February, 2011 - Yuri Diogenes's Blog - Site Home - TechNet Blogs

Yuri Diogenes's Blog

Thoughts from a Senior Technical Writer @ Microsoft Windows iX IT PRO Security Team

February, 2011

Posts
  • Yuri Diogenes's Blog

    Forefront TMG Update 1 Rollup 3 is now Available

    • 4 Comments

    The Update 1 Rollup 3 for Microsoft TMG 2010 is now available for you. This rollup address the following issues:

    KB article

    Title

    2501646

    FIX: "A security package specific error occurred" error when you run a recurring report on a Forefront TMG 2010 server that is managed by an EMS and that is in a workgroup

    2502685

    FIX: "0xc0360007 (STATUS_IPSEC_CLEAR_TEXT_DROP)" error when you try to access the internal IP address of a Forefront TMG 2010 server through an IPsec site-to-site network

    2472894

    "HTTP/1.1 502 - Error 11 Bad format" error when you access SSL websites that use SAN certificates in Forefront TMG Server 2010 if a non-English version of a Windows operating system is installed

    2501650

    FIX: "Page Cannot Be Displayed" error when you try to access a website that requires a client certificate authentication on a Forefront TMG client in Forefront TMG 2010 if HTTPS Inspection is enabled

    2501776

    FIX: "502 Proxy Error. An attempt was made to load a program with an incorrect format. (11)" error when you try to use a HTTPS URL through Forefront TMG 2010 if HTTPS inspection is enabled

    2498831

    How to configure the "HTTPS inspection caching in a forward proxy scenario" and "HTTPS inspection inclusion list" features in Forefront TMG 2010

    2498837

    An enterprise node is incorrectly added in Forefront TMG MMC after you install Forefront TMG 2010 SP1 Update 1

    2445386 

    "Sign in as a Different User" does not work on a SharePoint website that is published by Forefront TMG 2010

    2498835 

    PPTP or L2TP/IPsec connection is not reestablished between Forefront TMG 2010 servers

    2501777 

    FIX: "502 Proxy Error. An unknown error occurred while processing the certificate. (-2146893017)" error when you try to access a website over HTTPS in Forefront TMG 2010 if HTTPS inspection is enabled

    2497959

    Forefront TMG Firewall service may stop when users run desktop sharing software over HTTPS that is proxied by Forefront TMG 2010

    2500737

    "0xc0040446" or "0xc004041d" error if the primary IP address or DNS address uses 128.0.0.0/16, 191.255.0.0/16, or 223.255.255.0/24 in Forefront TMG 2010

    2497858

    SCOM logs many "Forefront TMG Server - Cache: Current Cache Fetches Average Ms Per Request error" error alerts from TMG Management Pack through Forefront TMG 2010

    2501755

    Mspadmin.exe may crash if you do not use SQL Server Express to log traffic in Forefront TMG 2010

    2502686

    Forefront TMG Firewall service might crash when WP_TRAFFIC tracing is enabled in Forefront TMG 2010

    2501782

    "0xc004039E" error when you use the "Allow user override" setting for a HTTP deny rule in an enterprise policy in Forefront TMG 2010

    2501780

    FIX: Forefront TMG Job Scheduler service (Isasched) stops responding on an array member server that is not a report server in Forefront TMG 2010

    As you can see there are a lot of fixes in this rollup, I particularly worked in many issues involving 2501650 and 2502686 while the hotfixes were not even ready. Due the nature of those issues I strong recommend you to download this update and plan the installation on your Forefront TMG. To install this update, you must have TMG 2010 SP1 and Update 1 already installed.

    Got get it at  http://support.microsoft.com/kb/2498770.

  • Yuri Diogenes's Blog

    Secure Access to your Cloud Services with Forefront TMG

    • 0 Comments

    Greetings!

    The article that I wrote for TechNet Magazine February issue is now available, you can access it from the link below: 

    image

    http://technet.microsoft.com/en-us/magazine/gg607680.aspx

    This article will give you a better picture of how Forefront TMG can assist your cloud migration by enhancing secure Internet access to the cloud services.

    Enjoy!

  • Yuri Diogenes's Blog

    Windows Security Survival Guide

    • 0 Comments

    Yesterday I post my first WiKi article, it is about Windows Security and the core Windows foundation to cover the security triad (Confidentiality, Integrity and Availability). Many IT Pros sometimes jump directly to try to hardening the system without first step back and analyze the business needs as well as how to cover the core security triad using built in resources available on Windows OS. This article will cover this discussion.

    You can access this article from the link below:

    http://social.technet.microsoft.com/wiki/contents/articles/windows-security-survival-guide.aspx

    The Microsoft TechNet WiKi is a great resource for exchanging experiences by writing content that you feel will be useful for the community. If you have a need and you look for an article and don’t find it, why not you write your own article under Microsoft TechNet? That’s the goal here, to make sure that you can help the community to succeed. Here are some articles that you should read before get involved on this:

    Get yourself engaged and enjoy working with such great community!!

  • Yuri Diogenes's Blog

    Talk TechNet with Keith Combs and Matt Hester – Episode 11: Yuri Diogenes on Forefront Threat Management Gateway

    • 0 Comments

    Registration is open for Episode 11 of Talk TechNet:

    https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032477768&EventCategory=4&culture=en-US&CountryCode=US

    Looking forward to chat with you about TMG as Secure Web Gateway.

  • Yuri Diogenes's Blog

    See you around Forefront Edge Community

    • 9 Comments

    I created this blog back in February 2008 and since that day I really tried to bring to you interesting troubleshooting techniques based on real scenarios. This blog was always something that I drove on my own free time (not that I have lot of free time), but I tried to managed my time in such way that posting here was part of my regular agenda. The numbers below show how much the traffic increased over the last couple of years in this blog and I would like to thank you all for contributing with that, is because I know you are reading that I feel energized to keep writing.

    image


    I can safely say that 90% of the posts that I wrote for this blog were related to ISA/TMG, which makes a lot of sense to me as I was working for CSS Forefront Edge Team. Yes, you read it right, I “was”. Starting Monday (Feb 14th) I will be fully dedicated to the Windows Security Team as a Technical Writer. As one of the co-authors of the Forefront TMG Administrator’s Companion Book and Forefront TMG Deployment Guide, I plan to keep writing about Forefront TMG here, but certainly will not be on the same frequency as before since I will be dedicated to Windows Security subject. From now on I will be more engaged in produce content that will be available in other locations, such as:

    http://technet.microsoft.com/en-us/windowsserver/windows-server-security.aspx

    http://social.technet.microsoft.com/wiki/contents/articles/wiki-it-security-portal.aspx

     

    There are some initiatives on the Forefront TMG space that I’m still engaged during this transition phase, which are:

    • MVP Summit 2011 – I hope to see all my MVP friends there, my presentation will be on Wednesday March 2nd (first two sessions in the morning).
    • Talk TechNet – I will be on Episode 11 of Talk TechNet to discuss about Forefront TMG as Secure Web Gateway. More details will soon be available here.
    • TechNet Magazine Article – a new article that I wrote for TechNet Magazine about using TMG to assist on BPOS deployment will be available on TechNet Magazine February issue (expected to be out by Feb 21st).

     

    Again, thanks a lot for visiting this blog and I hope to keep partnering with you in 2011, now in a broader way.

     

    Stay Safe!!

  • Yuri Diogenes's Blog

    Inbound TLS SMTP Traffic gets TCP Reset when published through TMG 2010

    • 0 Comments

    Consider a scenario where you are publishing a SMTP Server that uses TLS on Forefront TMG 2010, in such scenario TMG resets the connection to the SMTP client when the SMTP server closes its connection to TMG with a TCP FIN packet. This behavior can cause some specific SMTP client applications to report that message delivery failed even though messages are sent correctly. In this scenario you also will see the following entry on the Live Logging: Incoming SMTP Server    0x80074e24 FWX_E_CONNECTION_KILLED. This problem is documented for ISA Server 2006 in KB 959312. Recently we also experienced the same issue with TMG and the script from KB 959312 fixed the issue. After running this script on TMG you should see the message below on your command prompt windows (which should be opened in privileged mode):

    image

    After this change such behavior should go away…and yes, we will update this KB to include TMG.

    Note: only run this script on TMG if you are experiencing exactly the same behavior as explained in KB 959312.

Page 1 of 1 (6 items)