Figure 2 – Typical LDAP Traffic (click here to enlarge this picture).
Note: on this example TMG is 10.10.10.69 and the DC is 10.10.10.10
The LDAP search that is marked in the above traffic sample is exactly the location where this marker will be registered. If you use LDP.EXE you can browse through the location shown below:

Figure 3 – LDP Tool result.
When accessing this location, the right panel should show the value that has the TMG AD Marker that was registered as shown below:
Expanding base 'CN=Winsock Proxy,CN=Internet Gateway,CN=Services,CN=Configuration,DC=contoso,DC=com'...
Getting 1 entries:
Dn: CN=Winsock Proxy,CN=Internet Gateway,CN=Services,CN=Configuration,DC=contoso,DC=com
cn: Winsock Proxy;
distinguishedName: CN=Winsock Proxy,CN=Internet Gateway,CN=Services,CN=Configuration,DC=contoso,DC=com;
dSCorePropagationData: 0x0 = ( );
instanceType: 0x4 = ( WRITE );
keywords (2): Winsock Proxy; ISAServer;
name: Winsock Proxy;
objectCategory: CN=Service-Connection-Point,CN=Schema,CN=Configuration,DC=contoso,DC=com;
objectClass (4): top; leaf; connectionPoint; serviceConnectionPoint;
objectGUID: a87cf902-1b5a-4532-a9cb-bef8dd663fed;
serviceBindingInformation: http://ftmgfw.contoso.com:8080/wspad.dat;
serviceClassName: Winsock Proxy Service;
showInAdvancedViewOnly: TRUE;
uSNChanged: 496989;
uSNCreated: 496988;
whenChanged: 10/22/2009 9:08:54 AM Pacific Daylight Time;
whenCreated: 10/22/2009 9:08:53 AM Pacific Daylight Time;
3. Testing Client Configuration
To test the configuration on the client side you can use the FWCTool that comes with TMG Client, which is installed by default in %programfiles%\Forefront TMG Client folder. Follow the steps below to perform this test:
1. On the client workstation, open command.
2. Navigate to the location where TMG Client is installed.
3. Run the command fwctool TestAutoDetect
Here it is an output sample of this command when perform all tests successfully:
FwcTool version 7.0.7733.100
Forefront TMG Client support tool
Copyright (c) Microsoft Corporation. All rights reserved.
Action: Test the auto detection mechanism
Type: Default
Detection details:
Timeout is set to 60 seconds
Locating WSPAD URL on the Active Directory server
WSPAD object was found in the global Active Directory container
WSPAD URL found on the Active Directory server:
http://ftmgfw.contoso.com:8080/wspad.dat
Initializing Web server connection
Resolving IP addresses for ftmgfw.contoso.com
Resolved 1 address(es):
10.10.10.69
Connecting to address #1: 10.10.10.69:8080
Waiting for address #1 to connect
Address #1 successfully connected
Requesting wspad.dat file
Web server is connected and ready to send WSPAD file
Downloading WSPAD file
WSPAD file was downloaded successfully
Detected Forefront TMG: FTMGFW:1745
Result: The command completed successfully.
The highlighted text above is your confirmation that the AD registration was correctly found by the TMG Client.
Author
Yuri Diogenes
Sr Security Support Escalation Engineer
Microsoft CSS Forefront Edge Team
Technical Reviewers
Bala Natarajan
Sr Security Support Escalation Engineer
Microsoft CSS Forefront TMG Beta Team
Eric Detoc
Escalation Engineer
Microsoft CSS Forefront TMG Beta Team