Forefront Edge Security - Installation, Upgrade, and Setup ForumA forum for the discussion of issues and ideas regarding Forefront Threat Management Gateway (TMG) and ISA Server installation, upgrade, and setup© 2009 Microsoft Corporation. All rights reserved.Tue, 01 Dec 2009 12:11:59 Zbc4774d5-6ddb-4cb4-8613-d376d914728ehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/734baaf6-ea51-4be1-ba11-846c99b2cc4ehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/734baaf6-ea51-4be1-ba11-846c99b2cc4eNiclas Holmkvisthttp://social.technet.microsoft.com/Profile/en-US/?user=Niclas%20HolmkvistISA 2006 - NLB on Internal<p>Two ISA 2006 servers in an ISA array with NLB.</p> <p>Config:</p> <p>ISA01<br/>WAN: 10.10.10.100<br/>LAN: 192.168.1.100</p> <p>ISA02<br/>WAN: 10.10.10.101<br/>LAN: 192.168.1.101</p> <p>External - Primary VIP: 10.10.10.102<br/>VIP: 10.10.10.103</p> <p>Internal - Primary VIP: 192.168.1.102<br/>? 192.168.1.103</p> <p>Exchange 2007 CAS01<br/>192.168.1.110</p> <p>Exchange 2007 CAS02<br/>192.168.1.111</p> <p><br/>1. I've published Outlook Web Access for Exchange 2007 against a DNS name for 10.10.10.103 and that works fine. Access to the Exchange 2007 CAS servers (webfarm) is from 192.168.1.100 and 192.168.1.101 which is also ok (confirmed by IIS logs). Must I add a VIP to the Internal net (I.E 192.168.1.103) to get NLB to work on the Internal net and to get that IP address (I.E 192.168.1.103) to access the CAS servers?</p> <p>2. If ISA01 or ISA02 fails, can I expect that the Outlook Web Access session will be moved to the remaining ISA array node and the user doesn't need to logon again?<br/><br/>Thanks<br/>Niclas</p>Mon, 30 Nov 2009 09:37:45 Z2009-12-01T12:11:59Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/0ec2b517-b8b1-4c59-867e-4f3d2bf6a84ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/0ec2b517-b8b1-4c59-867e-4f3d2bf6a84aunclehughiehttp://social.technet.microsoft.com/Profile/en-US/?user=unclehughieISA Server 2006 on Windows Server 2008 RC0<p align=left><font face=Arial size=2></font> </p>Does it run?Sun, 02 Dec 2007 23:07:03 Z2009-11-30T20:15:12Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/bda747ce-30c3-41b1-a048-3595684a3b93http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/bda747ce-30c3-41b1-a048-3595684a3b93PatLamhttp://social.technet.microsoft.com/Profile/en-US/?user=PatLamWhere to find current Wormlist version<p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'">Hi all,</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'"> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>In my SCOm I get messages about Out of date Forefront engines. </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>In Scanner Updates (in Forefront console) I can see that all engines are up to date except the worm list. For worm list this is what I see:</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>Engine version: 10.1.2.234</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>Last checked 26/11/1009</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>Last update: 16/09/2009</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>Is there a place (online) where I can see what engine versions I should have to be up to date?</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>Thx for help,</span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US> </span></p> <p class=MsoNormal style="margin:0cm 0cm 0pt"><span style="font-size:10pt;color:#365f91;font-family:'Verdana','sans-serif'" lang=EN-US>Patrick</span></p>Thu, 26 Nov 2009 11:08:14 Z2009-11-27T10:57:05Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e72eb1d1-ce57-47cc-bf77-8d96ea29cba8http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e72eb1d1-ce57-47cc-bf77-8d96ea29cba8JSjagerhttp://social.technet.microsoft.com/Profile/en-US/?user=JSjagerISA 2006 VPN with and without RadiusWe having trouble setting up vpn access. We need 2 different type of vpn-connections. <br/>We are using a server on the web, which access a internal database through VPN (This one does not use radius authentication). This is a webservices that uses a ip-address (given buy ISA/AD) to connect to our ISA-server. Is it poissible to change this to a not-VPN-connection or should we use a sit2site connection?<br/>we want to give our 64bit mobile users access through a MS-VPN connection with radius-authentication.<br/>According to ISA it is not possible to use 2 ways of authentication on VPN.<br/><br/>So the question is:  Is this possible.Fri, 20 Nov 2009 08:00:11 Z2009-11-25T08:28:07Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/964089fd-7b2d-427b-8293-04e0c4e963f3http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/964089fd-7b2d-427b-8293-04e0c4e963f3GILSupporthttp://social.technet.microsoft.com/Profile/en-US/?user=GILSupportConfig high availability Isa Server<span class="long_text"><span style="background-color:#fff" title="una pregunta sobre NLB.">a question about NLB.<br/></span><span style="background-color:#fff" title="Voy a montar 2 ISA Server 2006 en NLB para tener alta disponibilidad y">I'm going to mount 2 ISA Server 2006 NLB to have high availability and </span><span style="background-color:#fff" title="balanceo de carga.">load balancing.<br/><br/></span><span style="background-color:#fff" title="Lo que voy a ahacer es lo siguiente:"><span style="background-color:#ebeff9" title="Lo que voy a hacer es lo siguiente:">What I will do is the following</span><br/><br/></span><span style="background-color:#fff" title="SRVISA01 (srvisa01.domain.es)">SRVISA01 (srvisa01.domain.es)<br/></span><span style="background-color:#fff" title="WAN: 64.155.166.101 --&gt; NIC1">WAN: 64.155.166.101 -&gt; NIC1<br/></span><span style="background-color:#fff" title="LAN: 10.10.10.101 --&gt; NIC2">LAN: 10.10.10.101 -&gt; NIC2<br/></span><span title="MASK: 255.255.255.0">MASK: 255.255.255.0<br/></span><span title="NLB virtual IP : 10.10.10.1">NLB Virtual IP: 10.10.10.1<br/></span><span style="background-color:#fff" title="IntraArray: 172.16.1.101 --&gt; NIC3">IntraArray: 172.16.1.101 -&gt; CIN3<br/><br/></span><span title="SRVISA02 (srvisa02.domain.es)">SRVISA02 (srvisa02.domain.es)<br/></span><span title="WAN: 64.155.166.102 --&gt; NIC1">WAN: 64.155.166.102 -&gt; NIC1<br/></span><span title="LAN: 10.10.10.102 --&gt; NIC2">LAN: 10.10.10.102 -&gt; NIC2<br/></span><span title="MASK: 255.255.255.0">MASK: 255.255.255.0<br/></span><span title="NLB virtual IP 10.10.10.1">NLB virtual IP 10.10.10.1<br/></span><span title="IntraArray: 172.16.1.102 --&gt; NIC3">IntraArray: 172.16.1.102 -&gt; CIN3<br/><br/></span><span title="DC (dc.domain.es) -- CSS server">DC (dc.domain.es) <br/></span><span title="LAN: 10.10.10.20 --&gt; NIC1">LAN: 10.10.10.20 -&gt; NIC1<br/></span><span title="MASK: 255.255.255.0">MASK: 255.255.255.0<br/></span><span title="GW: 10.10.10.1">GW: 10.10.10.1<br/><br/></span><span title="Esta todo OK o tambien debo de crear una NLB virtual IP Externa."><span class="long_text"><span style="background-color:#fff" title="1.- Esta todo OK o tambien debo de crear una NLB virtual IP Externa (Creo que no porque eso seria si quiero balancear servidores VPN, Publicaciones u otro caso, pero estos dos ISA solamente actuaran de Proxy.).">1 .- Is everything OK or should I also create a virtual NLB IP External (I think not because that balance would be if I VPN servers, publications or other event, but these two ISA Proxy only to act.).<br/><br/></span><span title="2.- El CSS donde lo instalo.">2 .- The CSS where I install it. </span><span style="background-color:#fff" title="En los propios servidores ISA01 e ISA02 o se puede instalar en otros servidores miembros del dominio?">In isa01 and ISA02 own servers or can be installed on other servers domain members? </span><span style="background-color:#fff" title="Que consejo me dais.">What advice would you give.</span></span></span></span>Thu, 19 Nov 2009 19:52:48 Z2009-11-26T03:41:54Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/46b9b03e-e2f4-438c-b5d1-3270b5092dfehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/46b9b03e-e2f4-438c-b5d1-3270b5092dfeThom Berrehttp://social.technet.microsoft.com/Profile/en-US/?user=Thom%20BerreNot able to manually set ExtendedRights on RecieveConnector - Exchange 2010 Edge and Forefront TMG 2010 RCIm trying out these products and ran into an issue configuring the RecieveConnector. <div><br/></div> <div>Using TMG Beta 3 and Exchange 2007 edge role I was able to manually grant Authenticated users extended rights on the external recieveconnector without TMG overwriting the settings.<br/> <div><br/></div> <div>Now it looks like TMG overwrites my manually set ExtendedRights on the RecieveConnector. I tried to set this to support IMAP users' need to send mail via SMTP externally. To achieve this I have tried to manually set permissions like ms-Exch-SMTP-Accept-Authoritative-Domain-Sender, ms-Exch-SMTP-Accept-Any-Recipient etc to Authenticated users on the connector.</div> <div><br/></div> <div>So what I'm trying to do is to grant users that use IMAP externally rights to submit messages from my Exchange Organization via the external RecieveConnector.</div> <div><br/></div> <div>As TMG immediately overwrites my manual settings I need to find a way to work around this. Is there another best practice to get this functionality?</div> <div><br/></div> <div>Thom </div> <div> </div> <div>  </div> </div>Sun, 22 Nov 2009 18:37:08 Z2009-12-01T09:03:17Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/f7a22c0d-f9c9-4adc-ac0e-db66b6366e46http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/f7a22c0d-f9c9-4adc-ac0e-db66b6366e46AlvaroMottahttp://social.technet.microsoft.com/Profile/en-US/?user=AlvaroMottaISA schemaHi Folks, greetings.<br/><br/>Our customer has an ISA 2000 installed on his network and it has the ISA Server schema installed on the AD.<br/>We are going to install an ISA 2006 and will manually migrate the rules from the 2000.<br/><br/>The question is: Does the ISA 2006 installation messes up the ISA 2000 schema in a way that we won't have means to have both ISAs productive while we are migrating the rules? If it does not have any impact, are there any Microsoft official link that we could use to prove to the customer that we will not impair his security with schema issues?<br/><br/>As far as I have seen, ISA 2004 and 2006 doesn't install any schema on the AD. If that holds true, does any of you recommend cleaning up the AD from the old ISA installation? If so, how to do that.<br/><br/>Thanks in advance.<br/><br/>Best regards,<br/><br/>ALTue, 17 Nov 2009 13:59:34 Z2009-11-18T13:51:33Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ba0cd586-dede-423b-afea-0a9b62c9e153http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ba0cd586-dede-423b-afea-0a9b62c9e153yusufuhttp://social.technet.microsoft.com/Profile/en-US/?user=yusufuTMG 2010 Configure as Inline ModeI wanted to know can we deploy TMG 2010 in inline mode , that is it would just be doing the monitoring and logging of user activity, but no do any kind of Web Filtering etc. <br/>I have a scenario where we want that the user who connect to the Internet their traffic should pass through the TMG , and the TMG would only record the activity. Ideally we want the TMG to act like a sniffer with the port connecting to the Firewall  as the Source Port and the TMG acting as the Destination .<br/>Thu, 12 Nov 2009 07:26:16 Z2009-11-20T02:21:24Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8793ec7a-a140-476f-ab43-42d2b1b8b88dhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8793ec7a-a140-476f-ab43-42d2b1b8b88dMohammad Nasirihttp://social.technet.microsoft.com/Profile/en-US/?user=Mohammad%20NasiriCan ISA Server 2006 authenticate users in domain when it is located in a workgroup ?Hello Friends :<br/><br/>I have a standalone ISA Server 2006  installed, and i also have an active directory domain, can ISA server authenticate users from active directory when it is not joined to it ?<br/><br/>thank you.<hr class="sig">Network is my LOVESun, 08 Nov 2009 18:33:07 Z2009-11-13T07:37:15Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/14f81b88-74c9-431d-baa4-9d5c2d5e9b91http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/14f81b88-74c9-431d-baa4-9d5c2d5e9b91Amathushttp://social.technet.microsoft.com/Profile/en-US/?user=AmathusISA 2006 Network and routing Help please?Hi all, <br/><br/>I have a problem that I am stuggling with, and need some help please?<br/><br/>Here is what I have:<br/><br/>3 leg ISA configuration, external IP, 192.x.x.x for DMZ and 10.0.0.1 - 10.0.7.255 for the internal network.<br/><br/>IThe internal network split in two, Site A IP range 10.0.0.1/22 and Site B 10.0.4.0/22 with a router 10.0.3.1 and 10.0.7.1 inbetween. <br/><br/>ISA internal IP address is 10.0.0.1 located at Site A.<br/><br/>Client PC DHCP default gateway is 10.0.0.1 (ISA Server) at site A and 10.0.7.1 (router) at Site B.<br/><br/>What I would like to do, or should I say, have to do, is to direct all traffic destined for site B to be routed via ISA to the router for site B (10.0.3.1).<br/><br/>At the moment, we are planning to replace the existing firewall and do an inplace swap, therefore keeping the exitxting firewall static route. I am trying to preconfig ISA so that we can just unplug the old firewall, and pop in the ISA server.<br/><br/>Does anyone know how to route all 10.0.4.1/22 traffic through a specific router?<br/><br/>Thanks,<br/><br/>Amathus. Wed, 04 Nov 2009 08:57:29 Z2009-11-07T16:12:58Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/b4c5e036-cfee-47b5-a597-b6ee5d981711http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/b4c5e036-cfee-47b5-a597-b6ee5d981711Isaac2k2http://social.technet.microsoft.com/Profile/en-US/?user=Isaac2k2ISA Firewall Policy ruleHi,<br/><br/>I have ISA 2006 setup and running. I created a rule for access to the isa server using the following protocols &quot;Microsoft CIFS (TCP) and NetBios Session&quot;. Withe this rule, I can connect to the isa server drives using \\server name\c$.<br/><br/>The problem I have right now is not sure what rule to create to enable isa server connect to other systems drives on the internal network. Also when I do nslookup on the isa server, i get:<br/><br/>DNS request timed out.<br/>    timeout was 2 seconds.<br/>*** Can't find server name for address 172.xx.xx.xx: Timed out<br/>Default Server:  UnKnown<br/>Address:  172.xx.xx.xx<br/><br/>Note: I can connect to this systems via their IP address but not by their dns names.<br/><br/>Any one with any idea?<br/><br/>Thanks <hr class=sig> Isaac2k2Tue, 27 Oct 2009 13:51:51 Z2009-11-04T12:32:46Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/7d1f3ca3-bd3a-4157-b453-4650582dc9b5http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/7d1f3ca3-bd3a-4157-b453-4650582dc9b5mnevanshttp://social.technet.microsoft.com/Profile/en-US/?user=mnevansTMG MBE installation errorHello,<br/> <br/> Getting an error on the installation of TMG MBE. It says &quot;Setup failed while registering Forefront TMG filters&quot;<br/> <br/> Installing on 2K8R2, member server &amp; tried stand-alone. Has 2 networks physically connected and statically assigned addresses. Have installed (what I've read/been told) are the pre-reqs, but maybe I missed one. Install log available upon request.<br/> <br/> Please help!Mon, 02 Nov 2009 18:45:33 Z2009-11-03T19:50:15Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/2cbdd235-928f-46d9-9ec3-6966a709c714http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/2cbdd235-928f-46d9-9ec3-6966a709c714Wai Yiphttp://social.technet.microsoft.com/Profile/en-US/?user=Wai%20Yipaccess rule for Argent remote monitoring of ISA server 2006Hi,<br/>We need to perform remote monitoring of ISA server 2006 using Argent TCP port 3190 from an Argent server. Our ISA server 2006 is multihomed with 2 NIC. We added a new access rule from Argent server to localhost for TCP 3190 but it doesn't work. The access is still denied recorded in the ISA logs. Appreciate any help to enlighten me. The Argent server is located in the Internal network. Thank you.Mon, 19 Oct 2009 08:53:35 Z2009-11-03T05:10:09Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/6333534f-82b7-4aaf-99aa-96dcd03a4b89http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/6333534f-82b7-4aaf-99aa-96dcd03a4b89proline1000http://social.technet.microsoft.com/Profile/en-US/?user=proline1000ISA 2004 Web Proxy Auto DiscoverHi,<br/>I was wondering if it would be possible for auto discover to work with this setup. We have 2 connections to the internet, one is for our network and the other is for a guest wireless.  I am trying to set up auto discover on the guest wireless. The server specs, the operating system is Windows 2003 R2 and ISA 2004 Enterprise with 3 NICs and is part of our domain. NIC 1 connects to a wireless access point that has dhcp running that users will initially connect to. NIC 2 connects to our network to access active directory for users to authenticate against. NIC 3 connects to a managed router that goes out to the internet.  If a user specifies the ip address for the proxy in internet options, the user will be prompt for credentials and it works.  Since this server is part of our domain and we already have 2 DCs both running dns and dhcp and the guest wireless users can not access the domain, Can autodiscovery work in this setup?Tue, 22 Sep 2009 15:20:25 Z2009-11-02T21:16:22Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/72fcf10e-bcea-4e04-932b-4f2efa131352http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/72fcf10e-bcea-4e04-932b-4f2efa131352trung tranhttp://social.technet.microsoft.com/Profile/en-US/?user=trung%20tranTMG RC and Exchange EdgeHi, I've configured TMG with Exchange Edge. I can receive mail however send mail doesn't work. Does anyone know what might be the cause? The edge server is getting the send connectors created with the subscription file. <br/> <br/> -Trung<br/> <br/> UPDATE: After looking at the firewall logs, it's saying that there is a failed connection attempt via SMTP from Exchange 2010 RC to the TMG server (with Exchange Edge). I've enabled the system rule that allows for this. <br/> <br/>Thu, 29 Oct 2009 16:56:38 Z2009-10-29T16:56:38Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ef6f76db-cf3c-4e7f-a866-6d78cc1457aehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ef6f76db-cf3c-4e7f-a866-6d78cc1457aeSergey Sypalohttp://social.technet.microsoft.com/Profile/en-US/?user=Sergey%20SypaloTMG Cluster SSetupHi All!<br/><br/>   Now we have 2 ISA 2006 Ent with following config:<br/>   Primary config storage on the same computer<br/>   Second pointing on other ISA Server<br/>   No Clustering (NLB, CARP etc) configured<br/><br/>Now i'm prepare to moving to TMG Ent and cluster configuration<br/><br/>I'm setup one EMS Server with config storage, and 2 TMG Ent Servers, as described <a href="http://isaserver.org/tutorials/Configure-Forefront-TMG-integrate-TMG-Array.html">http://isaserver.org/tutorials/Configure-Forefront-TMG-integrate-TMG-Array.html</a><br/>But after joining to array and entering to EMS Server and open TMG Console, in Internal network properties i cannon see NLB tab, and version of server switched to standart (and button Upgrade is present, asking me a key). Also in System status both servers marced red with error cannot connect to specified server. After Disjoining one server from array i can see NLB tab in internal network properties. So i have following questions:<br/><br/>1) Is it possible to store configuration on same server as TMG and alternate is second TMG (as configured now) or i need dedicated servers for config storage (no more that 2 servers are planned per array, in Enterprise will be 2 arrays with 2 nodes in array)<br/>2) Do i need to configure internal network properties for array and creating rules for allow traffic within array on EMS Server before joining TMG Servers to array or not? <hr class=sig> MCSE: M+S, SMS/SCCM, CCNATue, 27 Oct 2009 09:40:24 Z2009-11-04T08:12:49Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/3b8505c8-2dcf-4baa-be1c-e848d637e26bhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/3b8505c8-2dcf-4baa-be1c-e848d637e26brhelmerhttp://social.technet.microsoft.com/Profile/en-US/?user=rhelmerTMG RC: Getting Started Wizard fails in Configure Network Settings<p>I installed the TMG RC on a fresh install of Windows 2008 R2 Std. (joined to the domain) last night.  The setup went flawlessly (love the prerequisites handler!).  However, I cannot get past the Configure Network Settings phase of the Getting Started Wizard.  I selected the &quot;3-leg perimeter&quot; option.  <br/><br/>The network setup looks something like this:<br/><br/>LAN<br/>IP: 192.168.1.254<br/>Subnet mask: 255.255.255.0<br/>Default gateway: (blank)<br/>DNS: 192.168.1.200<br/><br/>Internet:<br/>IP: (static public IP address)<br/>Subnet mask: 255.255.255.248<br/>Gateway: (gateway for that subnet)<br/>DNS: (ISP DNS)<br/><br/>DMZ<br/>IP: 192.168.100.254<br/>Subnet mask: 255.255.255.0<br/>Default gateway: (blank)<br/>DNS: (blank, also tried 192.168.1.200)<br/><br/><br/>When I click Finish at the end of the setup, it gives a variety of errors (unfortunately, it doesn't list which NIC is the &quot;specified network adapter&quot;):<br/><br/>0xC004045E: The list of DNS addresses for the specified network adapter includes duplicates.<br/><br/>0xC004045C: The list of IP addresses for the specified network adapter includes duplicates.<br/><br/>Or 0x80004005: Unspecified error.<br/><br/><br/>I've tried quite a few things--backing out and setting up the NIC properties directly then re-running the Configure Network Settings wizard, uninstalling TMG and reinstalling and re-running the wizard, and starting from scratch with a complete reinstall of Windows, TMG, and re-running the wizard.  Any thoughts?<br/><br/>Thanks!<br/>Ryan</p>Tue, 20 Oct 2009 16:47:39 Z2009-10-29T06:52:56Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/456f0fa4-3a43-4245-9a5c-ce315b315183http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/456f0fa4-3a43-4245-9a5c-ce315b315183Paul Keijzershttp://social.technet.microsoft.com/Profile/en-US/?user=Paul%20KeijzersProblem creating rules and then test or view properties<p>I have installed Win 2008 R2 build7600(RTM) in a hyperv machine connected to a domain then installed TMG RC<br/>This all looks fine then i created a new array and a publishing rule for a website.<br/><br/>When i try to open the properties i get following critical screen<br/><a href="http://www.twitpic.com/la36e">http://www.twitpic.com/la36e</a><br/><br/>after a whole lot of ignores it shows properties but this is no good. then when i try to run the test it prompts me again with errors.<br/><br/>Can someone tell me what is going on and if there is a solution to this problem?<br/><br/>kind regards,<br/><br/>Paul Keijzers<br/><a href="http://www.kbworks.nl">Http://www.kbworks.nl</a></p>Mon, 26 Oct 2009 10:45:40 Z2009-10-27T13:53:00Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8ef7669f-bf8e-42f0-9b68-049c78345306http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8ef7669f-bf8e-42f0-9b68-049c78345306Mohammad Nasirihttp://social.technet.microsoft.com/Profile/en-US/?user=Mohammad%20NasiriTrihomed ISA Hello friends :<br/><br/>I have a network with two subnets , and one active directory database , i want to place all the servers in one subnet and all the clients in the other in order to control access and get reports of them , i also want to share internet for the client computers , I decided to use ISA server 2006 Enterprise sp1 with a trihomed structure, I do not have any public services :<br/><br/>1-Can i place the Domain Controller in the other subnet ?<br/>2-Can ISA Server handle theses amount of traffic ?<br/>3-What kind of hardware should i use to handle ISA with these amount of traffic ? ( i have DL-380- ML-580 HP Servers )<br/>4-I do not want ISA to be a single point of failure ! ( How can i implement NLB or FAilover for ISA )<br/><br/>Is there any guide or solution about this ?<br/><br/>Please help.<hr class="sig">Network is my LOVESun, 25 Oct 2009 03:20:47 Z2009-10-26T07:13:02Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/64a6047b-8a22-4d34-8b43-39d05ada3bb1http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/64a6047b-8a22-4d34-8b43-39d05ada3bb1ksnbhttp://social.technet.microsoft.com/Profile/en-US/?user=ksnbwhich type of template for exchange pop, imap, owa and proxy?We have deployed isa 2006 sp1. We are currently deployed in a single nic configuration, only using it for proxy for a couple of servers.<br/>We've added exchange 2007 owa and activesync. We now need to change the ISA template so we can publish secure pop and imap, as well.<br/>We already have edge servers deployed and they are firewalled and secured via an alternate method, not isa.<br/>We would like isa behing the edge servers and the exchange CAS/hub behind isa.<br/>I'm just getting familiar with isa and don't quite know where to put the 2nd nic. I was thinking of not changing the isa template, just add the 2nd nic to a perimeter network. and use that ip for the outside facing. It will get it's nat from a different firewall, not from isa.<br/>Will that work?<br/>Is there a better way?Fri, 23 Oct 2009 23:01:31 Z2009-10-26T16:30:48Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/406fe6c9-3be3-44c8-bcd8-f4266d56d566http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/406fe6c9-3be3-44c8-bcd8-f4266d56d566mashalehhttp://social.technet.microsoft.com/Profile/en-US/?user=mashalehTMG installation errorIam trying to install Microsoft Forefront Threat Management Gateway, but i get this error<br/>setp failed while registering forefront TMG filter<br/><br/>what is the problem and how to solve it plzWed, 21 Oct 2009 10:15:24 Z2009-10-29T06:53:46Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ca772fae-eb55-4cbf-9168-b4128efaab5chttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ca772fae-eb55-4cbf-9168-b4128efaab5cTinTin.Luihttp://social.technet.microsoft.com/Profile/en-US/?user=TinTin.LuiHow to configure NLB not using ISA NLB integrationHi, <div><br /></div> <div>Currently we are using ISA with NLB integration. But now we need to change the NLB affinity from single affinity to no affinity. Therefore we disabled the NLB integration in ISA and try to configure NLB using NLB manager.</div> <div><br /></div> <div>But we can only configure one node NLB. We got "Could not locate NLB on the specified computer" when connecting to other node. Is there any suggestion to configure ISA NLB with no affinity?</div>Wed, 14 Oct 2009 07:02:34 Z2009-10-21T03:45:50Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/c4a67684-0fd3-4b95-b714-ad58aeb2bf0ehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/c4a67684-0fd3-4b95-b714-ad58aeb2bf0eJack Hachttp://social.technet.microsoft.com/Profile/en-US/?user=Jack%20HacIssue after applying kb916106 on the ISA Server 2004After applying kb916106, it kissed all the external access (incoming\outgoing), we had to remove it, anyone has similar issues?Fri, 16 Oct 2009 15:33:24 Z2009-10-16T17:34:48Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8f22f86a-8f64-4910-934f-c4471b7cc40ahttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8f22f86a-8f64-4910-934f-c4471b7cc40aergomyhttp://social.technet.microsoft.com/Profile/en-US/?user=ergomyTMG 2010 RC fails to install due to Windows SP not installed<p>The preparation tool reports that the "required windows server 2008 service pack" is not installed and stops the installation.&nbsp; But, the server has SP 1 installed.&nbsp; <br /><br />Winver reports that the server is running Version 6.0 (Build 6001: Service Pack 1).&nbsp; The hardware is an Intel 64 bit dual&nbsp;quad core that is running hyper-v.<br /><br />In addition to SP 1 the Server Window Updates are competely up to date.&nbsp; Can anyone tell me what might be going wrong with the prep tool step?&nbsp;</p>Wed, 14 Oct 2009 15:29:43 Z2009-10-16T04:23:08Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/f4c45aa8-ea33-4a19-ae1e-ac70a129fb21http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/f4c45aa8-ea33-4a19-ae1e-ac70a129fb21radical93http://social.technet.microsoft.com/Profile/en-US/?user=radical93Cannot Joined the Workstation to D.C. thru ISA Server 2006Good day Guyz,<br /><br />&nbsp;&nbsp;&nbsp;&nbsp; I'm also at the Visual Foxpro General Forum, but I also here at Windows Server Forums because I have been a hard times to be able to joined one of the workstations at D.C. thru ISA Server below are the following informations:<br /><br />&nbsp;&nbsp;&nbsp;&nbsp; Windows Server 2003 SP2 - A.D. DNS Integrated, Domain Controller<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 NIC Card&nbsp;- Public IP Address&nbsp;of 178.197.225.194/27<br /><br />&nbsp;&nbsp;&nbsp;&nbsp; Windows Server 2003 SP2, ISA Server 2006 - Member Server of A.D.&nbsp;DNS Integrated, Domain Controller, DHCP, RRAS<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;3 NIC Card:<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1st NIC Card - Public IP Address of 178.197.225.195/27<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;2nd NIC Card - Private IP Address of 172.18.0.1/16 - Internal Network<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3rd NIC Card - Private IP Address of 172.17.0.1/24 - for VPN Clients<br /><br />&nbsp;&nbsp;&nbsp;&nbsp; Windows XP Pro SP2<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1 NIC Card:<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; With IP Address of 172.18.0.6<br /><br />&nbsp;&nbsp;&nbsp;&nbsp; At ISA Server 2006 Firewall:<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1.&nbsp;Created Internal (172.18.0.0 - 172.18.255.255) - Networks&nbsp;<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2. Created&nbsp;All Access with Route Internal to External - Network Rules<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3. Created DHCP Request, DHCP Reply - Firewall Policy<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 4. Created LAN Internet Access - Firewall Policy<br />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;5. Created Server Internet Access - Firewall Policy<br /><br />&nbsp;&nbsp;&nbsp;&nbsp; All are working fine but I cannot joined my Workstation WinXP to Domain Controller, should I make another Firewall Policy to be able to joined workstations? any idea to help me out, thanks guyz...Wed, 07 Oct 2009 18:13:34 Z2009-10-09T18:09:50Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/a50e272c-fc75-4627-9194-8a6fe7f16d27http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/a50e272c-fc75-4627-9194-8a6fe7f16d27Amelsforthttp://social.technet.microsoft.com/Profile/en-US/?user=AmelsfortTMG Beta3: STOP-error from netio.sysToday I installed Forefront TMG Beta 3 on my Windows 2008 R2-server (Enterprise). After installing, my system wouldn't reboot anymore. It's loading Windows, then starts loading the system-configuration and then I get a BSOD telling me about a 'DRIVER IRQ LESS OR EQUAL'. The source is the file netio.sys.<br/><br/>Does anyone know what could be wrong? I guess it has something to do with the network-drivers or the filter TMG installs, but when I start in Safe Mode with Networking, I'm able to boot and log on.<br/><br/>This system used to be a DC, but I demoted it before installing TMG.<br/><br/>I hope someone has had the same problem or know a solution.Thu, 01 Oct 2009 20:14:40 Z2009-10-07T20:05:29Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8da6cb35-fc11-4b91-8b24-c91efbca3ad6http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/8da6cb35-fc11-4b91-8b24-c91efbca3ad6GlenVhttp://social.technet.microsoft.com/Profile/en-US/?user=GlenVMoving ISA Server 2000 to a new ServerWe have ISA Server 2000 running on a Windows 2000 Server.&nbsp; I've bought a new Server to be based on Windows 2003.<br /><br />Is there a simple way to move the&nbsp;existing ISA Server 2000 setup, configuration and rules to the new Server?Sun, 04 Oct 2009 14:17:08 Z2009-10-12T02:18:17Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/4c030025-b6c0-4c39-8018-89daabfbe5aehttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/4c030025-b6c0-4c39-8018-89daabfbe5aeahmedilyashttp://social.technet.microsoft.com/Profile/en-US/?user=ahmedilyasVPC and ISA Server configuration help!<p>I'm using VPC's here and just cannot seem to make this happen. <br/><br/>I want all traffic to go through ISA Server but this does not seem to be working. <br/><br/><br/>I am using VPC's here and ISA 2006.</p> <p><br/>however, when pinging or access say the exchange server VPC, it pings just fine and bypasses ISA completely. <br/><br/>What am I doing wrong? <br/><br/>I want to eventually publish exchange and other apps through ISA Server but cannot do this until this configuration is sorted. <br/><br/>how should my VPC's be configured?</p> <p>This is my configuration:</p> <p> </p> <p><strong>VPC Settings:</strong> <br/><br/>Client WS2003: Local Only <br/>DC/AD/DNS: Local Only <br/>Exchange 2003: Local Only <br/>OCS: Local Only <br/>ISA Server: LoopBack Adapter #2, Host NIC, Loopback Adapter #3 <br/><br/><br/><strong>IP Settings in the VPC's</strong> <br/><br/>Client WS2003: <br/>IP: 10.10.10.3 <br/>Subnet: 255.255.255.0 <br/>Default Gateway: 10.10.10.1 <br/><br/><br/>DC/AD/DNS: <br/>IP: 10.10.20.1 <br/>Subnet: 255.255.255.0 <br/>Default Gateway: 10.10.20.2 <br/>DNS: 127.0.0.1 <br/><br/><br/>Exchange 2003 <br/>IP: 10.10.20.3 <br/>Subnet: 255.255.255.0 <br/>Default Gateway: 10.10.20.2 <br/>DNS: 10.10.20.1 <br/><br/><br/>OCS: <br/>IP: 10.10.20.5 <br/>Subnet: 255.255.255.0 <br/>Default Gateway: 10.10.20.2 <br/>DNS: 10.10.20.1 <br/><br/><br/>ISA Server: <br/>LoopBack Adapter #2 (Internal) IP: Obtain IP Automatically <br/><br/>LoopBack Adapter #3 (External) <br/>IP: 10.10.10.1 <br/>Subnet: 255.255.255.0 <br/><br/>NIC (Contoso Networl): <br/>IP: 10.10.20.2 <br/>Subnet: 255.255.255.0 <br/>DNS: 10.10.20.1 <br/><br/>Where am I going wrong? <span class=info><br/><br/></span></p> <p> </p> <p><br/>I am not a pro so please can someone explain step by step on what the configurtion should be rather than just posting links? <br/><br/>Thanks! </p><hr class="sig">Need 2 be back @ MS - MS All the way! Follower since 1995 MS Super Evangelist| MSDN Forums ModeratorMon, 28 Sep 2009 16:36:14 Z2009-10-07T07:27:18Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e40ffeb7-f1ba-4a31-bdc8-63b77bb7e184http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e40ffeb7-f1ba-4a31-bdc8-63b77bb7e184mani999http://social.technet.microsoft.com/Profile/en-US/?user=mani999Reverse Proxy HTTP > HTTPS and vice versa.<span style="font-size:small;color:#004080;font-family:Calibri"><span style="font-size:small;color:#004080;font-family:Calibri"><span style="font-size:small;color:#004080;font-family:Calibri"> <p dir=ltr>Hello, <br/>I have an issue with reverse proxying and looking for guidance.<br/><br/>We have an issue with translating information between HTTPS and HTTP between two servers and are attempting to use ISA server 2006 on a windows 2003 box in the middle to pass data back and forward.<br/><br/>http traffic from the internal server1 must be re-formatted to https traffic and sent to internal  server 2 whilst https traffic from the internal server 2 must be converted to http to send to internal server 1. Is ISA 2006 capable of this, and if so which would be the best (only) method for achieving it?<br/><br/>I'm completely stumped.<br/>Thanks in advance for any help.<br/></p> </span></span></span>Wed, 09 Sep 2009 15:33:34 Z2009-09-16T08:53:23Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/2f51e8da-c72a-40a8-a79c-8d3762ecc59bhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/2f51e8da-c72a-40a8-a79c-8d3762ecc59bAlvaroMottahttp://social.technet.microsoft.com/Profile/en-US/?user=AlvaroMottaISA 2006 as upstream for ISA 2000<p>Hi folks.</p> <p><br/>We have a pair of ISA 2000 enterprise that will be upgraded to ISA 2006 enterprise. They are configured as an NLB array.</p> <p>This array has another ISA 2000 enterprise as a downstream proxy. Due to changes on the AD architecture in the near future, the upgrade of this downstream proxy will be postponed for a while.</p> <p>The question is:<br/>Can the ISA 2006 work as upstream proxy for ISA 2000? Are there any official documentation from microsoft regarding this specific issue?</p> <p>Thanks in advance.</p> <p><br/>Regards,</p> <p>AL</p> <p> </p>Fri, 11 Sep 2009 15:02:11 Z2009-11-17T14:07:30Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/7d16aaa9-9105-4729-8f3e-7f89af1affd8http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/7d16aaa9-9105-4729-8f3e-7f89af1affd8SP1 can not be installed on ISA 2006http://social.technet.microsoft.com/Profile/en-US/?user=SP1%20can%20not%20be%20installed%20on%20ISA%202006SP1 can not be installed on ISA 2006<p>Dear Admin:<br/><br/>    I installed ISA 2006 to a Windows 2003 server, but when I install SP1 for the ISA 2006, I met a error, the detailed information was attached, can you have some solutions regarding this case, thank you so much, good day.<br/><br/><strong>Event Type: Error<br/>Event Source: LoadPerf<br/>Event Category: None<br/>Event ID: 3009<br/>Date:  9/8/2009<br/>Time:  12:11:59 PM<br/>User:  N/A<br/>Computer: N/A<br/>Description:<br/>Installing the performance counter strings for service w3proxy (w3proxy) failed. The Error code is the first DWORD in Data section.</strong></p> <p><strong>For more information, see Help and Support Center at </strong><a href="http://go.microsoft.com/fwlink/events.asp"><strong>http://go.microsoft.com/fwlink/events.asp</strong></a><strong>.<br/>Data:<br/>0000: f2 03 00 00 b3 11 00 00   ò...3...</strong></p>Tue, 08 Sep 2009 05:15:30 Z2009-09-14T02:54:25Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/04398cdd-5912-446f-9408-91e4ada04cc4http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/04398cdd-5912-446f-9408-91e4ada04cc4Dubl Dhttp://social.technet.microsoft.com/Profile/en-US/?user=Dubl%20DSplit Routing/Source IP RoutingI want to find out if it is possible to do split routing/source IP routing on ISA 2006/Forefront Edge Security server. <br/><br/>Here is my scenario:<br/><br/>1x ISA/Forefront Edge Security server<br/>2x DSL Internet connections<br/>30x Client computers<br/><br/>I need to configure the Edge Security Server in such a way that 10 of the client computers use the second DSL line for all internet traffic and the rest of the clients use the first DSL line.Tue, 08 Sep 2009 14:28:28 Z2009-09-09T13:36:48Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e144e71c-3270-4050-9eb5-c87758350ad7http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e144e71c-3270-4050-9eb5-c87758350ad7AngelStarhttp://social.technet.microsoft.com/Profile/en-US/?user=AngelStarISA 2006 Network Load BalancingDear Technet Members,<br/><br/>I have two ISA 2006 SP1 servers in an array on Win2k3 SP2 servers, and two configuration servers on seperate servers Win2k3 SP2. I have confgirured NLB using ISA console for my internal interface, which works just fine.<br/><br/>One of my ISA server NLB members has weeker hardware compared to the other ISA server. I need to tell NLB that the server which is more powerfull has more connection than the other one.<br/><br/>In advance thank you<br/>Fri, 04 Sep 2009 08:37:24 Z2009-09-09T06:53:12Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/06bfe215-9e4a-4c1e-bb88-a66868fe86b5http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/06bfe215-9e4a-4c1e-bb88-a66868fe86b5JohnABGhttp://social.technet.microsoft.com/Profile/en-US/?user=JohnABGTMG Beta 3 installation just stopsHi, <br/>I downloaded both SE and EE versions and got the same result: <br/>the preparation tool ran successfully - all items indicated 'no action taken' (already installed) <br/>then the message &quot;all required prerequisites have been installed&quot; and &quot;Launch TMG Setup&quot; box is checked -- I click &quot;finish&quot; (the only button) and the window closes and the TMG installation does not start.  Retried several times with the same result. <br/><br/>Some details: <br/>- This server is not a member of a domain <br/>- Running Windows 2008 64-bit (AMD) on a vm server. <br/>- 2 GB ram<br/>- One NIC <br/><br/>What are we doing wrong? <br/><br/>We appreciate any assistance. <br/>Thanks, <br/>John<br/><br/>Wed, 15 Jul 2009 00:41:05 Z2009-09-03T11:16:44Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/477d8b3d-34ad-4be6-94c7-b03697e0d17fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/477d8b3d-34ad-4be6-94c7-b03697e0d17fJohn Gwinnerhttp://social.technet.microsoft.com/Profile/en-US/?user=John%20GwinnerRoutes that don't correlate with the network adapter - 10.x.x.x (cluster) mixed in with the Internet Adapter (edge network)<p>I keep getting the following alert:<br/><br/><span><strong>Description: </strong></span><span>ISA Server detected routes through the network adapter T1 that do not correlate with the network to which this network adapter belongs. When networks are configured correctly, the IP address ranges included in each array-level network must include all IP addresses that are routable through its network adapters according to their routing tables. Otherwise valid packets may be dropped as spoofed. The following ranges are included in the network's IP address ranges but are not routable through any of the network's adapters: 10.255.255.255-10.255.255.255;. Note that this event may be generated once after you add a route, create a remote site network, or configure Network Load Balancing and may be safely ignored if it does not re-occur.<br/><br/>I have configured our FIrewall servers as Edge servers.<br/><br/>We have an external addreses range with a public IP, the T1 adapter mentioned above.<br/><br/>I have an internal NIC with 192.168 addresses for the protected network.<br/><br/>I have a 3rd NIC with 10.x.x.x as the Cluster Interconnect.<br/><br/>I've check both the IPConfig, and the T1 adapter doesn't have the 10.x.x.x associated with it:<br/><br/></span><span></span></p> <pre>Ethernet adapter Cluster: Connection-specific DNS Suffix . : IP Address. . . . . . . . . . . . : 10.10.42.2 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : Ethernet adapter T1: Connection-specific DNS Suffix . : IP Address. . . . . . . . . . . . : x.x.x.246 Subnet Mask . . . . . . . . . . . : 255.255.255.248 IP Address. . . . . . . . . . . . : x.x.x.243 Subnet Mask . . . . . . . . . . . : 255.255.255.248 IP Address. . . . . . . . . . . . : x.x.x.242 Subnet Mask . . . . . . . . . . . : 255.255.255.248 IP Address. . . . . . . . . . . . : x.x.x.244 Subnet Mask . . . . . . . . . . . : 255.255.255.248 Default Gateway . . . . . . . . . : x.x.x.241 Ethernet adapter Internal LAN: Connection-specific DNS Suffix . : IP Address. . . . . . . . . . . . : 192.168.253.251 Subnet Mask . . . . . . . . . . . : 255.255.0.0 Default Gateway . . . . . . . . . : PPP adapter RAS Server (Dial In) Interface: Connection-specific DNS Suffix . : IP Address. . . . . . . . . . . . : 172.20.0.128 Subnet Mask . . . . . . . . . . . : 255.255.255.255 Default Gateway . . . . . . . . . :<br/><br/></pre> and here's the route print:<br/> <pre>IPv4 Route Table =========================================================================== Interface List 0x1 ........................... MS TCP Loopback interface 0x10005 ...00 21 91 19 9e d0 ...... D-Link DGE-560T PCI Express Gigabit Ethernet Adapter 0x50002 ...00 13 72 fc 06 9d ...... Broadcom NetXtreme Gigabit Ethernet 0xa0003 ...00 13 72 fc 06 9c ...... Broadcom NetXtreme Gigabit Ethernet #2 0xc0004 ...00 53 45 00 00 00 ...... WAN (PPP/SLIP) Interface =========================================================================== =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 xx.xxx.xxx.241 xx.xxx.xxx.244 10 10.10.42.0 255.255.255.0 10.10.42.2 10.10.42.2 10 10.10.42.2 255.255.255.255 127.0.0.1 127.0.0.1 10 10.255.255.255 255.255.255.255 10.10.42.2 10.10.42.2 10 xx.xxx.xxx.240 255.255.255.248 xx.xxx.xxx.244 xx.xxx.xxx.244 10 xx.xxx.xxx.242 255.255.255.255 127.0.0.1 127.0.0.1 10 xx.xxx.xxx.243 255.255.255.255 127.0.0.1 127.0.0.1 10 xx.xxx.xxx.244 255.255.255.255 127.0.0.1 127.0.0.1 10 xx.xxx.xxx.246 255.255.255.255 127.0.0.1 127.0.0.1 10 68.255.255.255 255.255.255.255 xx.xxx.xxx.244 xx.xxx.xxx.244 10 72.19.61.220 255.255.255.255 xx.xxx.xxx.241 xx.xxx.xxx.244 10 127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1 172.20.0.0 255.255.255.128 10.10.42.1 10.10.42.2 1 172.20.0.128 255.255.255.255 127.0.0.1 127.0.0.1 50 172.20.0.130 255.255.255.255 172.20.0.128 172.20.0.128 1 192.168.0.0 255.255.0.0 192.168.253.251 192.168.253.251 10 192.168.253.251 255.255.255.255 127.0.0.1 127.0.0.1 10 192.168.253.255 255.255.255.255 192.168.253.251 192.168.253.251 10 224.0.0.0 240.0.0.0 10.10.42.2 10.10.42.2 10 224.0.0.0 240.0.0.0 xx.xxx.xxx.244 xx.xxx.xxx.244 10 224.0.0.0 240.0.0.0 192.168.253.251 192.168.253.251 10 255.255.255.255 255.255.255.255 10.10.42.2 10.10.42.2 1 255.255.255.255 255.255.255.255 xx.xxx.xxx.244 xx.xxx.xxx.244 1 255.255.255.255 255.255.255.255 192.168.253.251 192.168.253.251 1 Default Gateway: xx.xxx.xxx.241 =========================================================================== Persistent Routes: None</pre> <br/><br/>I've checked the Enterprise and the Array configuration, but I don't see anything setup wrong there (or the overlapping of the 10.x addresses with the array).<br/><br/>I have a DNS record that makes server-fwall-1b and server-fwall-2b 'point' to the 10.10.42.1 and 10.10.42.2 IP addresses, which are the cluster interconnect static IP's.<br/><br/>Any ideas? I think this is preventing NLB from functioning correctly.<br/><br/>Thanks!<br/><hr class="sig">== John ==Sat, 15 Aug 2009 01:16:59 Z2009-08-31T22:10:03Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ee76dcca-57b0-414d-a6c4-1613e036ffd6http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/ee76dcca-57b0-414d-a6c4-1613e036ffd6Toyin Ogunmefunhttp://social.technet.microsoft.com/Profile/en-US/?user=Toyin%20OgunmefunColocating ISA 2006 and WSUS on the same serverI will like to know f it possible to isa 2006 in a single nic mode and also runs wsus service on it at the same time.<br/><br/>The client only have one server to use as against my initial advise on spliting th service onto two different hardware.<br/><br/>if the co-location is supported by Microsot best pratices, I will appreciate links that confirms and explain the configuration involve.<br/><br/>Thanks in advance<br/><br/>ToyinThu, 27 Aug 2009 15:26:13 Z2009-09-04T03:49:38Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/76eeb670-ef01-4af1-8f15-127d44ee9d9fhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/76eeb670-ef01-4af1-8f15-127d44ee9d9farmando20http://social.technet.microsoft.com/Profile/en-US/?user=armando20TMG Beta3 installationI am installing TMS Beta3 on a new windows 2008  std server 64 bit with two nics not a member of a domain yet it will be, I also UAC is disenabled . I tried installing but it stops after notified me of items that need to be preinstalled it istructs me to click on Finish to install. It stops.<br/><br/>I did. I followed the instructions but it stopped when I clicked FINISH. I am very frustrated. I get no errors.Fri, 14 Aug 2009 17:30:29 Z2009-08-24T01:34:28Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/bf30e0b1-3139-46a7-933d-e3ad9cb3cd47http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/bf30e0b1-3139-46a7-933d-e3ad9cb3cd47hadi2979373http://social.technet.microsoft.com/Profile/en-US/?user=hadi2979373"Failed to run ADAM setup Error : 0x80074e46" with Windows 2003 SP2 and ISA 2006 installationHi,<br><br>I have encountered the error message <br><br>&quot;Failed to run ADAM setup Error : 0x80074e46&quot;<br><br>Here are the excerpt that i have obtained from ISA installation log :<br><br>12:50:50 ISA setup CA INFO   : Running command line: C:\WINDOWS\ADAM\adaminstall.exe /answer:&quot;C:\Program Files\Microsoft ISA Server\ADAM\\AdamAnsFile.ini&quot;<br>12:51:10 ISA setup CA ERROR  : Installation of the ISA instance (ADAM) failed. hr: 0x80074e46<br>12:51:10 ISA setup CA INFO   : ADAM source log file: C:\WINDOWS\DEBUG\adamsetup.log, destination file: C:\WINDOWS\TEMP\ISAADAM_INSTALL_813.log<br>12:51:10 ISA setup CA ERROR  : Failed to run ADAM setup. Error: 0x80074e46<br>12:51:10 ISA setup CA ERROR  : ExecuteAdamSetup: Adam_Install(1) failed, hr=0x80074e46<br>12:51:10 ISA setup CA ERROR  : ExecuteAdamSetup failed<br>12:51:10 ISA setup CA ERROR  : DisplayPopup: Setup failed to install ADAM.<br>  (0x80074e46)<br>12:51:10 ISA setup CA INFO   : UI Level is  ok to display a message box<br>12:53:11 ISA setup CA ERROR  : EXIT: InstallADAM, Custom Action failed (0x643)<br><br>I have tried to manually install ADAM from Win 2003 R2 Disc 2 setup  as well as downloading manually the ADAM SP1 from http://www.microsoft.com/downloads/details.aspx?familyid=9688f8b9-1034-4ef6-a3e5-2a2a57b5c8e4<br><br>After i read further from this article below:<br>http://blogs.technet.com/isablog/archive/2007/03/27/isa-server-and-windows-server-2003-service-pack-2.aspx<br> it's related to Windows 2003 SP2. Fortunately i have Windows 2003 SP2 installed before installing ISA 2006<br><br><br>Please let me know how to resolve this issue.<br><br>Regards,<br><br>Hadi Teo.Sun, 16 Mar 2008 05:23:02 Z2009-08-31T09:00:36Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e8c96d3c-2a50-46e9-b685-13a5f08ba670http://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/e8c96d3c-2a50-46e9-b685-13a5f08ba670lmnickolhttp://social.technet.microsoft.com/Profile/en-US/?user=lmnickolISA 2006 Video Stream SplittingHi,<br/><br/>Does ISA 2006 have the capability of &quot;splitting&quot; a streaming video amound clients?  Currently we have ISA 2006 Standard Edition with SP1 installed.  We would like to stream a live video of a meeting to approximately 30 clients without destroying our network by using up all of the bandwidth.  I was hoping to have one feed from the video source to the proxy and then multiple feeds from the proxy to the clients.  I have read that ISA 2000 contained some software that did something similar to this but that was removed in the release of 2004.  I have not found whether or not 2006 has this capability.  If this is not a possiblity, do you have any recommendations for products that can handle this request?Tue, 11 Aug 2009 15:27:04 Z2009-08-20T03:36:31Zhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/5e3ef03d-0987-4438-9bc5-a71ee1d0908bhttp://social.technet.microsoft.com/Forums/en-US/Forefrontedgesetup/thread/5e3ef03d-0987-4438-9bc5-a71ee1d0908bT-Birdhttp://social.technet.microsoft.com/Profile/en-US/?user=T-BirdCan ISA 2006 Standard SP1 work under Svr 2008 Domain Functional Level ?<p>Can a legend out there please tell me if ISA 2006 standard with SP1 will function under the Windows Server 2008 Domain Functional Level ? Any reference I have seen says it must be 2003, e.g <a href="http://technet.microsoft.com/en-au/library/bb794821.aspx">http://technet.microsoft.com/en-au/library/bb794821.aspx</a>. I am wondering if this is just old info or is still relevant ?<br/><br/>Any lead to an official confirmation of this would be greatly appreciated.<br/><br/>Thanks,<br/><br/>Tony.</p>Thu, 06 Aug 2009 06:50:32 Z2009-08-07T02:01:58Z