<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ISA &amp;amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx</link><description>Introduction Microsoft Security Response Center (MSRC) issued bulletin MS08-037 to address vulnerabilities in DNS resolvers caused by predictable UDP source port usage. MSKB 956190 addresses behavior observed when traffic crosses a NAT-based firewall</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3113221</link><pubDate>Thu, 28 Aug 2008 10:13:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3113221</guid><dc:creator>PsYteAk</dc:creator><description>&lt;p&gt;Good article!&lt;/p&gt;
&lt;p&gt;Just wondering… &lt;/p&gt;
&lt;p&gt;Shouldn’t it be SecureNAT client instead of SecureNET? Or is it two different names for the same thing?&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3113452</link><pubDate>Thu, 28 Aug 2008 18:33:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3113452</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;I have a personal preference for &amp;quot;SecureNET&amp;quot; because it allows you to mentally consider the fact that the traffic flow from a host / application which is neither a Firewall client nor a Web Proxy client can be processed by a route relationship. &amp;nbsp;&amp;quot;SecureNAT&amp;quot; doesn't allow for this mental flexibility.&lt;/p&gt;
&lt;p&gt;..hope it's not too confusing...&lt;/p&gt;
</description></item><item><title>BlogMS Weekly Articles Published - 25th August 2008 to 31st August 2008</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3120838</link><pubDate>Mon, 08 Sep 2008 12:57:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3120838</guid><dc:creator>BlogMS - Official Microsoft Team Blogs</dc:creator><description>&lt;p&gt;body { font-family: Arial; font-size: 10pt} 183 Microsoft Team blogs searched, 88 blogs have new articles&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3151277</link><pubDate>Wed, 12 Nov 2008 01:19:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3151277</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;We've created updates to ISA and TMG to support source port randomization for UDP traffic across NAT relationships.&lt;/p&gt;
&lt;p&gt;You can obtain the update packages here:&lt;/p&gt;
&lt;p&gt;ISA 2000 (requires SP2): &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=1455d4e6-a0b5-4583-82f1-ee8239fca207"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=1455d4e6-a0b5-4583-82f1-ee8239fca207&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;ISA 2004 Std Ed (requires SP3): &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0ab83f12-653b-4be1-befe-594c4ef62baa"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=0ab83f12-653b-4be1-befe-594c4ef62baa&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;ISA 2004 Ent Ed (requires SP3): &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=55ce3623-2f7b-4900-9a2f-7e2aa2fe9c50"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=55ce3623-2f7b-4900-9a2f-7e2aa2fe9c50&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;ISA 2006 (requires SP1): &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e96a6e20-0c04-4c7d-9f3e-207b02ae29cc"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=e96a6e20-0c04-4c7d-9f3e-207b02ae29cc&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;TMG MBE: &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e974422f-42b0-426c-8852-ff8e67264909"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=e974422f-42b0-426c-8852-ff8e67264909&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>DNS/NAT update available for ISA and TMG</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3151290</link><pubDate>Wed, 12 Nov 2008 01:35:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3151290</guid><dc:creator>Yuri Diogenes's Blog</dc:creator><description>&lt;p&gt;We just released an update for ISA (2000, 2004 and 2006) and TMG MBE for the behavior that Jim Harrison&lt;/p&gt;
</description></item><item><title>ISA/TMG Updates zu MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3151581</link><pubDate>Wed, 12 Nov 2008 14:22:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3151581</guid><dc:creator>Forefront &amp; Security Blogs</dc:creator><description>&lt;p&gt;Wer heute in den WSUS geschaut hat, wird Updates f&amp;#252;r alle ISA Server-Versionen gefunden haben. These&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3154386</link><pubDate>Sun, 16 Nov 2008 06:51:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3154386</guid><dc:creator>Nori</dc:creator><description>&lt;p&gt;After installing this update PPTP stopped working.&lt;/p&gt;
&lt;p&gt;Only after removing it could I get PPTP to work again.&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3155447</link><pubDate>Mon, 17 Nov 2008 22:34:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3155447</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;Nori, have you contacted CSS?&lt;/p&gt;
&lt;p&gt;Can you elaborate on &amp;quot;stopped working&amp;quot;?&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3164386</link><pubDate>Fri, 05 Dec 2008 18:28:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3164386</guid><dc:creator>Kai Wilke</dc:creator><description>&lt;p&gt;After applying the patch, you're not able to establish PPTP connections to your ISA, because TCP 0.0.0.0:1723 stops listening for incomming PPTP calls.&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3165889</link><pubDate>Tue, 09 Dec 2008 21:46:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3165889</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;Due to some installation issues on Forefront TMG (MBE), the package at: &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=e974422f-42b0-426c-8852-ff8e67264909"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyID=e974422f-42b0-426c-8852-ff8e67264909&lt;/a&gt; has been re-released. &amp;nbsp;The code which manages the UDP NAT pool has not changed; only the installation process.&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3165896</link><pubDate>Tue, 09 Dec 2008 22:00:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3165896</guid><dc:creator>isablog</dc:creator><description>&lt;p&gt;Kai! - whereyabeen?!?&lt;/p&gt;
&lt;p&gt;Given that the update only allocates UDP sockets and PPTP operates on TCP:1723, this error doesn't male sense.&lt;/p&gt;
&lt;p&gt;I'll see if I can repro it. &amp;nbsp;If not, will you have cycles to provide more targeted data?&lt;/p&gt;
</description></item><item><title>Exception List Script for ISA Server and Forefront TMG UDP Updates</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3165926</link><pubDate>Tue, 09 Dec 2008 23:12:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3165926</guid><dc:creator>Forefront TMG (ISA Server) Product Team Blog</dc:creator><description>&lt;p&gt;Why do I need this? Last month, we released a collection of updates to help mitigate the problem caused&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3167185</link><pubDate>Thu, 11 Dec 2008 23:33:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3167185</guid><dc:creator>Nori</dc:creator><description>&lt;p&gt;I didn't have time to troubleshoot further why PPTP stopped working or contact CSS.&lt;/p&gt;
&lt;p&gt;So I just uninstalled.&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3241227</link><pubDate>Thu, 14 May 2009 17:32:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3241227</guid><dc:creator>RNA</dc:creator><description>&lt;p&gt;There is already a solution to the problem of PPTP ports disappeared? &lt;/p&gt;
&lt;p&gt;Already tried hotfix KB968078 that supersedes KB956570 but that has the same problem.&lt;/p&gt;
</description></item><item><title>re: ISA &amp; TMG NAT behavior And MS08-037 &amp; MS09-016</title><link>http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx#3241785</link><pubDate>Fri, 15 May 2009 18:27:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3241785</guid><dc:creator>Kai Wilke</dc:creator><description>&lt;p&gt;A few minutes ago i ran into the same PPTP issue again. Thx to MS09-016 for making trouble...&lt;/p&gt;
&lt;p&gt;Deinstalled MS09-016 and everything runs fine again. But now I'm sitting in front of a non-patched ISA box, again!&lt;/p&gt;
&lt;p&gt;Hope PSS will fix this issue soon, so that ISA admins would be finally protected against the Kaminsky DNS exploit.&lt;/p&gt;
&lt;p&gt;&amp;gt; Kai! - whereyabeen?!?&lt;/p&gt;
&lt;p&gt;Jim? (i guess, because nobody else would use the word &amp;quot;whereyabeen&amp;quot;) ;)&lt;/p&gt;
&lt;p&gt;I'm still in Berlin. But i've played in the last two years a little bit more with Cisco stuff than with ISA. &lt;/p&gt;
&lt;p&gt;Regarding the help... sure you can ping me via email. (kw at itacs dot de)&lt;/p&gt;
&lt;p&gt;-Kai&lt;/p&gt;
</description></item></channel></rss>