Forefront Server Security Management Console ForumDiscussions and questions on FSSMC© 2009 Microsoft Corporation. All rights reserved.Tue, 01 Dec 2009 09:06:15 Z8344880c-c33c-450f-820d-70ae555e2739http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/eed97a32-78b2-4ab8-ae03-8365dea6d1b8http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/eed97a32-78b2-4ab8-ae03-8365dea6d1b8digbyphttp://social.technet.microsoft.com/Profile/en-US/?user=digbypForefront Protection for Exchange Server Console link MissingI have installed Forefron 2010 and the console link is missing from the <strong>Microsoft Forefront Server Protection </strong>Group in All Programs. All I see is the readme link and link to Management Shell<br/><br/>Wed, 25 Nov 2009 10:59:35 Z2009-12-01T09:06:15Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/4e5279dc-00d6-43a1-baaa-210b085a39fdhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/4e5279dc-00d6-43a1-baaa-210b085a39fdSyam Swethahttp://social.technet.microsoft.com/Profile/en-US/?user=Syam%20SwethaFilling an already defined object from XML file through XSD fileHello every body,<br/><br/>Iam generating an xsd file using an object(class).Based on xsd file i got an xml file with data as an input.<br/>i need to fill the class from an XML file using XSD file.Can any body help how to achive this.<br/><br/>Thanks,<br/>SwethaThu, 19 Nov 2009 13:35:10 Z2009-11-26T10:20:41Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/91313c5c-2d80-42bf-bf9a-0689b1019335http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/91313c5c-2d80-42bf-bf9a-0689b1019335Chris Ryshichttp://social.technet.microsoft.com/Profile/en-US/?user=Chris%20RyshicInstall/launch issue with Forefront Security Server Management ConsoleI install the program fine but get an error stating that a security exception has been called when i try launching the program.<br/><br/>It states the site does not &quot;allow partially trusted callers&quot;?<br/><br/>Does anyone know of a fix for this?Wed, 11 Nov 2009 16:07:56 Z2009-11-18T17:58:35Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f8a9c57f-ed95-410f-83e6-aa606eb95b51http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f8a9c57f-ed95-410f-83e6-aa606eb95b51ngsolutionshttp://social.technet.microsoft.com/Profile/en-US/?user=ngsolutionsFSSMC with different forestHello,<br/><br/>I have two domains on two different forest with a one way trust relationship ( Domain B trust Domain A)<br/><br/>Domain A where my console is installed<br/>Domain B where my Exchange server and Antigen 9 are installed as well<br/>The Antigen Agent has been deployed successfully<br/>No I try to deploy a template but it doesn't works<br/>The error on server of domain B is <br/><span style="font-size:xx-small"> <p>Thu Nov 12 16:22:24 2009 ERROR SybSyncGetFile(&quot;file://\\&lt;server&gt;\SybariRedistribution$\packages\1\template.adb&quot;, &quot;C:\WINDOWS\Temp\SybariTemp\template.adb&quot;) reports error (0x00000005) Access is denied. Failed to access: <a>\\&lt;server&gt;\SybariRedistribution$\packages\1\template.adb</a><br/><br/>On server of Domain B I'm able to open UNC to server of Domain A where console is installed<br/><br/>All advices are welcome :-)<br/><br/>Regards</p> </span>Thu, 12 Nov 2009 15:30:29 Z2009-11-13T10:49:19Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/5396b2b1-7771-462e-88cb-ea12352b562chttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/5396b2b1-7771-462e-88cb-ea12352b562cBz2005s2khttp://social.technet.microsoft.com/Profile/en-US/?user=Bz2005s2kWhere are the data files for the Engine updates held in FSSMC???Does FSSMC hold the engine updates in the SQL instance or does it hold it on the local server?<br/><br/>In other words, do I need to worry about my local server drives filling up quickly over time or do I just need to make sure I have enough room on SQL?<br/><br/>Thanks,<br/><br/>BrandonWed, 11 Nov 2009 17:23:52 Z2009-11-12T03:25:22Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/2900eaa0-41d9-4321-bb6f-102c80195519http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/2900eaa0-41d9-4321-bb6f-102c80195519Loeyhttp://social.technet.microsoft.com/Profile/en-US/?user=LoeyI do not want to cache specific website<p>Hi,<br/><br/>I'm using ISA 2006 with 2 NIC, 1 is going to ISP and the other 1 is going to LAN (user). But I encounter 2 issues: <br/><br/><strong>1st</strong>- I can not access <a href="http://maps.google.com">http://maps.google.com</a> . I got this error code:</p> <ul class=adminList> <li>Error Code: 500 Internal Server Error. The request was rejected by the HTTP filter. Contact your ISA Server administrator. (12217) </li> <li>IP Address: 209.85.231.99 </li> <li>Date: 10/29/2009 4:51:59 AM [GMT] </li> <li>Server: GW01 </li> <li>Source: web filter </li> </ul> <p>I try to uncheck HTTP webfilter it works but caching does't work (cache hit ratio=0). Is there any other way?<br/><br/><br/><strong>2nd</strong>- Some website are using HTTP with authentcation are cache. How can i configure a specific website not to be cache or filter? <br/><br/>Please help.<br/><br/>Thanks</p>Thu, 29 Oct 2009 05:53:18 Z2009-11-20T23:21:24Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/5e82c976-b9a6-4383-9976-cdbeac20d2c4http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/5e82c976-b9a6-4383-9976-cdbeac20d2c4Xelahhttp://social.technet.microsoft.com/Profile/en-US/?user=XelahForefront TMG schedule half-hour increment<p>How to set half hours increments in forefront TMG Schedule?</p>Thu, 29 Oct 2009 12:28:09 Z2009-11-06T09:52:09Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f88ad6a3-eb04-40f0-9e7c-ddb512071f3dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f88ad6a3-eb04-40f0-9e7c-ddb512071f3dIsmayilhttp://social.technet.microsoft.com/Profile/en-US/?user=IsmayilISA2006 how to bypass as400 application via isa2006 server ?<br/>Wed, 21 Oct 2009 08:45:39 Z2009-10-31T09:03:56Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/141a979a-b2de-4e5a-b74b-c59028db394chttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/141a979a-b2de-4e5a-b74b-c59028db394cMarco Enxutohttp://social.technet.microsoft.com/Profile/en-US/?user=Marco%20EnxutoForefront Client Security<p>Hi there,<br/>It seems Microsoft Told in a blog post that FCS is supported in Win2008R2 and win7, which is not true.<br/>I've tried to install on my server and got errors with Microsoft Operation Manager 2005, which raised a wird error.... dont no why, or what it is because the log page presents an html table with empty values.<br/><br/>1st error was in the assesment, telling that i need more space on disc, which i have 250gb free for that.<br/>2nd error was what i told.... MOMServer error code is about prerequesites, but dont know which one i fail, cause theres nothing there....<br/><br/>So is there anyone knowing how to work around this?</p><hr class="sig">Marco Enxuto, Lisbon, Amadora, PortugalMon, 19 Oct 2009 01:38:20 Z2009-10-26T01:15:30Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/3073cd64-9daf-430a-8182-8b6f24972d30http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/3073cd64-9daf-430a-8182-8b6f24972d30MicroTeckhttp://social.technet.microsoft.com/Profile/en-US/?user=MicroTeckISA 2006 Routing ProblemHave ancountered a problem with routing traffic from ISA 2006 (LocalHost) to Publish Server. Example: Exchange 2007 forwards traffic to a Public IP address, this intern is NATTED from our ISP to ISA's external NIC (Exchange is able to send External and Internal Outbound mail but unable to recieve External Inbound Mail). I can see the traffic hitting the box but am unable to forwards the traffic from the Local Host to the Published Server (Sitting behind ISA), This problem is persistant with all existing NAT translations that existed on our Linux Firewall. This problem also occurs when traffic cannot be routed from the LocalHost ISA to our Internal Web Server.<br /><br />Your urgent assistance is need to resolve this problem.Wed, 14 Oct 2009 08:12:55 Z2009-10-16T08:08:50Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/55066ca0-6fd3-4b13-8c8b-f141d4b0ee7ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/55066ca0-6fd3-4b13-8c8b-f141d4b0ee7amoriteukhttp://social.technet.microsoft.com/Profile/en-US/?user=moriteukFSSMC shows all cluster nodes as passiveHi all,<br/><br/>I have installed FSSMC to managed our 2 exchange clusters. One of the clusters seems to be having some issues with FSSMC all nodes show up as passive with the same server on each node.<br/><br/>This is reporting wrongly on the engine versions report and is also stopping me from running the signature updates job on each of these nodes.<br/>Tue, 01 Sep 2009 07:06:04 Z2009-10-13T07:32:11Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1129f408-9058-441b-b1ee-889350d73031http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1129f408-9058-441b-b1ee-889350d73031robahthttp://social.technet.microsoft.com/Profile/en-US/?user=robahtIs there a possibility to schedule the retrieval of data in quarantine manager?<p>For our montly reports I have created a SQL query that collects the quarantine data from the SybariEnterpriseManager database. Only problem I have at this moment is that I'm not able to schedule the retrieval of quarantine data from the antigen servers to the FSSMC database. This is a manual job in the console. Maybe I have overlooked something but I can't find this option in FSSMC. <br />Mayby there is a possibility to script something to schedule the retrieval? Anybody any ideas?</p>Tue, 06 Oct 2009 07:42:14 Z2009-10-12T11:28:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/fddb6957-225f-4a1f-bb4f-63665b155509http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/fddb6957-225f-4a1f-bb4f-63665b155509windows12354http://social.technet.microsoft.com/Profile/en-US/?user=windows12354Pushing forefront out onto Windows server 2008 R2<span style="font-size: small;"><span style="font-family: Calibri;">I recently tried to push forefront out onto a server running windows server 2008 R2.<span>&nbsp; </span> It would not load forefront.<span>&nbsp; </span> I was wondering what I need to do to my main server (running windows server 2003) that pushes out forefront. <span>&nbsp;</span> To <span>&nbsp;</span> enable forefront to be used on my new server. BTW I use forefront and push it out to other computers on my network running Vista&hellip;.<span>&nbsp;&nbsp;</span> </span> </span>Sat, 10 Oct 2009 17:33:48 Z2009-10-19T07:32:47Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/50bc9948-6111-40e4-9229-82b2b3274183http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/50bc9948-6111-40e4-9229-82b2b3274183Creating a Script to Remove and Install MOM Agenthttp://social.technet.microsoft.com/Profile/en-US/?user=Creating%20a%20Script%20to%20Remove%20and%20Install%20MOM%20AgentHow To Do a Script to Remove / Install MOM AgentHi,<br/> <br/> I have 200 workstations with a MOM Agent installation being pointed to a server who is no longer a Forefront Management Server.<br/> <br/> What I am trying to do is:<br/> 1 - Add the firewall port exception to allow the server to communicate with the MOM agents<br/> 2 -  Remove the MOM Agent<br/> 3 - Install it again with other parameters (these being X:\InstalationCD\CLIENT\CLIENTSETUP.EXE /MS (our new management server hostname) /CG (our new configuration server hostname)<br/> <br/> I have gone as far as this in a batch script:<br/> <br/> netsh firewall add portopening all 1270 &quot;MOM Communication&quot; -&gt; Opens firewall port 1270 which is used for MOM Communication<br/> net use q: \\192.168.10.17\E -&gt; Map Network Drive where installation CD is located<br/> Q:\InstalationCD\CLIENT\CLIENTSETUP.EXE /MS CERBERUS /CG CERBERUS -&gt; Forefront Installation<br/> net use q: /delete /y -&gt; Delete Mapped Network Drive<br/> pause -&gt; pauses command prompt to check results of batch script<br/> <br/> However, I get an access denied message unless the user logging in is a local administrator.<br/> <br/> I see 3 possible workarounds for this:<br/> <br/> 1 - Check if the user is in the local administrators, add the user in local administrators group if it's not there and then remove it if it added the user.<br/> 2 - Do the above, but with 2 VB Scripts included (one to add the user and one to remove it after), running the batch script in between.<br/> 3 - To do everything above all in a VB Script, it would allow distribution via GPO which would be much more suitable but I'm just looking for a solution now.<br/> <br/> Is there such a script or another possible workaround?Thu, 24 Sep 2009 15:57:26 Z2009-10-07T07:26:48Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d76f8866-3fa6-407d-b29d-4afc2d756f55http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d76f8866-3fa6-407d-b29d-4afc2d756f55gianfelicehttp://social.technet.microsoft.com/Profile/en-US/?user=gianfeliceError installed AEMHi all, i try to installa AEM into a windows 2003 server with sql 2005 but at the end i receive this error message:<br/>ERROR 1001. ERROR EXECUTING SQL SCRIPT -&gt; MUST DECLARE THE SCALAR VARIABLE @MACHINEID.<br/>Into SQL i set SQL 2000 COMPATIBILITY.<br/>Can you help me?<br/>Many thanksThu, 01 Oct 2009 09:57:36 Z2009-10-09T01:44:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1515834e-aab0-49e3-8e34-08a4a601d55fhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1515834e-aab0-49e3-8e34-08a4a601d55fMarcus1976http://social.technet.microsoft.com/Profile/en-US/?user=Marcus1976ForeFront Server on a Windows 2008 64 bit server running SQL Server 2008?When trying to install on a server that already has SQL Server 2008, I get an error to the effect that SQL Server 2005 SP1 Reporting Services cannot be found.<br /><br />If I also install SQL Server 2005 Express edition with reporting services on the server, will everything have a happy ending?<br /><br />Any caveats?Sat, 03 Oct 2009 09:59:24 Z2009-11-12T15:43:49Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d4357566-84d9-4985-b678-bf69881af14dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d4357566-84d9-4985-b678-bf69881af14dSteve Kovacshttp://social.technet.microsoft.com/Profile/en-US/?user=Steve%20KovacsForefront Server Security Management Console on a backup server: "Password mismatch between the Primary and Backup Servers"<span style="font-size:7.5pt;color:#080808;font-family:'Verdana','sans-serif'">Can anyone give some guidence on a issue we're having with trying to setup FSSMC with Primary and Backup Servers?<br/><br/>On the Backup server we get the &quot;Password mismatch between the Primary and Backup Servers&quot; error which is covered by the follwoing kb article: <a href="http://support.microsoft.com/kb/946342"><span style="font-size:x-small">http://support.microsoft.com/kb/946342</span></a>.<br/><br/>The problem is that the <span style="color:#000000">language locales match and are both English. The only thing I can think is that the server language is set to English (NZ) and the SQL instance on that server is set to English (US). These settings are the same on both Primary and Backup servers.</span><br/><br/>The one thing that stands out is the default Collation setting for the SQL instance is Latin1_General_CP1_CI_AS and the databases are set to SQL_Latin1_General_CP1_CI_AS. I've seen in a Stirling forum that this was an issue and it was recommended that the SQL instance was created with the SQL_Latin1_General_CP1_CI_AS collation set.<br/><br/></span>Anyone hit this issue?<br/><br/>Mon, 07 Sep 2009 02:23:24 Z2009-10-05T07:28:15Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1d3aa41f-9d44-4356-b808-17c8fffd21ebhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1d3aa41f-9d44-4356-b808-17c8fffd21ebstubzyhttp://social.technet.microsoft.com/Profile/en-US/?user=stubzyFSSMC - How do I change the Replication PasswordHi <br/>I've setting up a Backup FSSMC server, but keep getting prompted that the passwords on the Primary and Backup server don't match.<br/><br/>How do I change the password on the Primary Server?<br/><br/>ThanksTue, 22 Sep 2009 13:28:19 Z2009-09-29T13:43:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d01788e3-b0e5-4fc5-a31e-a19b1f909e6dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d01788e3-b0e5-4fc5-a31e-a19b1f909e6dmoriteukhttp://social.technet.microsoft.com/Profile/en-US/?user=moriteukEngine versions reportHi all,<br/><br/>Environment:- FSSMC on a server, Exchange 2003 in clustered environment, antigen 9.0 sp1<br/><br/>When we run the engin versions report out clustered servers do not report on the antigen worm engine in the engine versions report. they just show &quot;0&quot;. the report is correct and upto date for the bridgehead servers with update from the 16th September showing.<br/>I have re-pushed the agents out to the clusted nodes but without any luck.<br/><br/>Does anyone have any ideas of what may be causing this or how to resolve it?<br/><br/>TIA<br/><br/>AndyThu, 24 Sep 2009 13:35:15 Z2009-10-02T06:48:58Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/00e7e119-9a68-40de-9e37-0c0c199d7a81http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/00e7e119-9a68-40de-9e37-0c0c199d7a81eidzeihttp://social.technet.microsoft.com/Profile/en-US/?user=eidzeiForefront on x64 file server?MS recommends installing an AV on all server products. Forefront has server flavours for select services (SharePoint, Exchange...). Which MS AV for file servers, Hyper-V servers, AD DS servers? Is it Forefront Client Security? Will it work on 64 bit Server OS's (I thought I just read they were not supported), if not what will?Mon, 21 Sep 2009 09:22:48 Z2009-09-22T12:50:54Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/a7ba18a4-a466-48bb-80d6-a54c1282818ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/a7ba18a4-a466-48bb-80d6-a54c1282818aAlex Carneirohttp://social.technet.microsoft.com/Profile/en-US/?user=Alex%20CarneiroApply / Templates through FSSMC<p align=left><font face=Arial size=2>When I deployed templates to Forefront Security for SharePoint (FSSP) through FSSMC, the settings are not loaded. I need to click on &quot;Load From Template&quot; button on FSSP to apply them.</p> <p> </p> <p align=left><font face=Arial size=2>Do you know, how to load templates settings without click on &quot;Load From Template&quot; button?</font></p> <p align=left> </p> <p align=left>Thank's</font></p>Tue, 20 May 2008 19:11:28 Z2009-09-24T13:38:44Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/7ce9d44a-9064-47c6-a58a-5dafe5a8f42chttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/7ce9d44a-9064-47c6-a58a-5dafe5a8f42cMarmekshttp://social.technet.microsoft.com/Profile/en-US/?user=MarmeksHow often Microsoft publishes updates for FCS?Greetings!<br/> Does anybody knows, how often Microsoft publishes updates for Forefront Client Security?Fri, 11 Sep 2009 11:04:33 Z2009-09-18T06:23:48Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/e9fb2764-b1af-479e-8a91-871bf50c93f1http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/e9fb2764-b1af-479e-8a91-871bf50c93f1moriteukhttp://social.technet.microsoft.com/Profile/en-US/?user=moriteuktemplate updatesI have setup FSSMC to manage our antigen sp1 servers and all seems to be ok. <br/><br/>My problem is that when I push out a filter list update the templete on each server updates automatically but it takes a little while for the actual smtp scan job to update with the changes. If I run &quot;antigenstarter tcfl&quot; on the server the smtp scan job updates immeadiately.<br/><br/>How is this update controlled automatically and can I configure the delay before each check/update<br/><br/>TIA<br/><br/>AndyWed, 09 Sep 2009 10:43:29 Z2009-09-25T07:06:52Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/ff09d20a-bf43-4a89-bfed-824276540719http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/ff09d20a-bf43-4a89-bfed-824276540719robahthttp://social.technet.microsoft.com/Profile/en-US/?user=robahtFSSMC says updates have failed, but Antigen 9 is already up to dateMaybe this is by design, i don't know. Maybe i configured something incorrect. We deployed FSSMC. It downloads the updates from the antigen download site and then distributes them to the Antigen 9 installations. Updates are done succesfully. The versions on the FSSMC, Antigen and the internet are the same. But, when I check the alert logs, I get these alerts:<br/><br/>exchsrvr01 28-7-2009 10:16:23 Server exchsrvr01 FAILED to update engine Microsoft AV <br/>exchsrvr01 28-7-2009 10:06:21 Server exchsrvr01 FAILED to update engine Antigen Worm List <br/>exchsrvr01 28-7-2009 10:05:21 Server exchsrvr01 FAILED to update engine CA Vet <br/>exchsrvr01 28-7-2009 10:03:27 Server exchsrvr01 FAILED to update engine Sophos Anti-Virus <br/>exchsrvr01 28-7-2009 10:02:26 Server exchsrvr01 FAILED to update engine Norman Data Defense <br/><br/>These alerts repeat themself every hour which makes sense because updates are downloaded and distributed in FSSMC every hour.<br/><br/>Antigen 9.0 does not have scheduled updates. Anyone an idea why this is happening?Tue, 28 Jul 2009 08:39:20 Z2009-09-02T19:35:33Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/97f916fb-9cdd-4d44-bbac-81cc36c0a13ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/97f916fb-9cdd-4d44-bbac-81cc36c0a13aHolly Kipp - MSFThttp://social.technet.microsoft.com/Profile/en-US/?user=Holly%20Kipp%20-%20MSFTHow IIS queries are handled for FSSMC jobs<span style="font-size:xx-small"> <p>Submitted by Paul Gruner - Microsoft<br/><br/>Symptoms</p> <p>=============================</p> <p>When sending web-based reports in Microsoft Forefront Server Security Management Console (FSSMC), you might receive following error: The GenerateAndSendReport function returned an error.</p> <p> </p> <p>Cause</p> <p>=============================</p> <p>When creating the first job in FSSMC, IIS is queried to check if authentication is enabled for FSSMC.</p> <p>There are two possibilities:</p> <p>1) If authentication is enabled, we set the default URL used for all web-based reports to https://localhost/FSSMConsole/</p> <p>2) If authentication is not enabled, we set the default URL used for all web-based reports http://localhost/FSSMConsole/</p> <p>Any following jobs created in FSSMC, will use this default URL. FSSMC does not query IIS anymore in order to verify if any changes to the security settings have been implemented.</p> <p>Resolution</p> <p>=============================</p> <p>The default URL for web-based reports is stored in SQL. The value containing the default URL is called SemURL, the database is called SybariEnterpriseManager and the table is called dbo.sdSettings.</p> <p>There are two established workarounds:</p> <p>1) Install Microsoft SQL Server Management Studio Express (SSMSE), and edit the SemURL value directly in the dbo.sdSettings table in SQL. In order to access this table, you can download a free copy of SSMSE from following location: http://www.microsoft.com/downloads/details.aspx?familyid=C243A5AE-4BD1-4E3D-94B8-5A0F62BF7796&amp;displaylang=en</p> <p>2) After making changes to the FSSMC security settings in IIS, delete all existing jobs and recreate them. This will force FSSMC to query the security settings of IIS again, upon the creation of the first job.</p> <p>Repro Steps</p> <p>=============================</p> <p>- Disable authentication in IIS for FSSMC</p> <p>- Create the first job in FSSMC</p> <p>- Enable authentication in IIS for FSSMC</p> <p>- Create a second job in FSSMC and send a web-based report for this job.</p> <p> </p> <p>More Information</p> <p>=============================</p> <p>This is a known issue and won't be fixed in a future release.</p> <p>References</p> <p>=============================</p> <p>Microsoft Forefront Server Security Management Console Version: 10.5.1241.0</p> </span>Mon, 31 Aug 2009 17:09:14 Z2009-08-31T17:09:14Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/30595d30-2134-463d-9d74-a61444947568http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/30595d30-2134-463d-9d74-a61444947568moriteukhttp://social.technet.microsoft.com/Profile/en-US/?user=moriteukFSSMC signature update locationsHi all<br/><br/>We have just upgrade to FSSMC to allow us to manage out exchange 2003 clusters that are running antigen 9 with sp1.<br/><br/>I am having a problem with the scanner updates in that when they are downloaded it seems to be putting them in the wrong path. When looking in the event viewer Antigen is looking for the manifest.cab file in C:\Program Files\Microsoft Forefront Security\Server\Server Management\Services\Redistribution\Cache\x86\&lt;enginename&gt;\package but when I download the updates it puts them in C:\Program Files\Microsoft Forefront Security\Server\Server Management\Services\Redistribution\Cache\x86\&lt;enginename&gt;\&lt;0908270004&gt;\x86\Microsoft\Package.<br/><br/>How do I change this so that the automatic updates will work<br/><br/>TIA<br/><br/>AndyFri, 28 Aug 2009 12:12:22 Z2009-09-24T13:36:01Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f25c5c62-302f-48e0-9342-7a7986897705http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f25c5c62-302f-48e0-9342-7a7986897705Allan Muhttp://social.technet.microsoft.com/Profile/en-US/?user=Allan%20MuSQL Express Edition on FSSMC primary server?Hi,<br/><br/>Just a quick question, is it possible to use SQL server 2005 Express Edition on FSSMC primary server, or we have to setup a seperate SQL server?<br/><br/>Thanks in advance!Tue, 18 Aug 2009 16:51:48 Z2009-08-26T16:12:07Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/99f37076-4b3f-41df-80e5-e1e09487dcdbhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/99f37076-4b3f-41df-80e5-e1e09487dcdbSparrohawkhttp://social.technet.microsoft.com/Profile/en-US/?user=SparrohawkSharepoint multi-tier setup: 2 FE and 1 APP serverI have two FE MOSS servers and one APP server. What is the best procedure for setting upr FSS.<br/><br/>Should FSS be installed on both FE's? That would make sense to me, but SP is smart enough to know this? <br/>Does the APP server need a copy. I wouldn't think so. <br/>Can you use two seperate installs of the FSS for each server and manage through a remote admin OR is it best to setup the FSS Management Console? <br/>Tue, 25 Aug 2009 19:14:40 Z2009-08-26T16:52:44Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/72a8c5ff-9997-40b2-98c9-a54749f63146http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/72a8c5ff-9997-40b2-98c9-a54749f63146Johnnymoreirahttp://social.technet.microsoft.com/Profile/en-US/?user=JohnnymoreiraRede wireless Acesso MACPessoal, tenho uma duvida, eu mando sinal via radio pra uns amigos meus, mais eles ta usando p2p e ta caindo a rede<br/> eu sei bloquear o p2p pelo ISA server na boa, mas o problema é que eu gostaria de pode liberar a mac deles pelo servidor e não pelo AP<br/> Por que pelo ap tem que fica reiniciando toda hora, eu gostaria de saber se o ISA tem essa função, liberar sómente as MAC cadastrada pra navegarSun, 16 Aug 2009 03:03:41 Z2009-08-16T03:03:42Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/912c9811-6c44-4c9e-8008-d56356f6a694http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/912c9811-6c44-4c9e-8008-d56356f6a694stick1701http://social.technet.microsoft.com/Profile/en-US/?user=stick1701Problem accessing Quarantine manager<p align=left><font face=Arial size=2>I have been working with the FSSMC and Forefront for Sharepoint over the past few days.  I have managed to get most of the things working, but I'm having trouble with the Quarantine manager.  If I use the same user account that installed FSSMC, the Quarantine manager loads fine and I can do whatever I need (pull data, remove info, etc).  Unfortunately, if I try to do this using my own account, it gives me a .NET error (I'll post it at the end since it is a big one).  My account has domain admin access, dbo access to the SQL databases (on a seperate SQL 2005 server), and is setup as a user in FSSMC.  Since it works as the account I used to install FSSMC, it has to be a rights issue somewhere.  Anybody run into this before or have an idea as to how I fix this?</font></p> <p align=left> </p> <p align=left><span></p> <h1>Server Error in '/FSSMConsole' Application. <hr width="100%" color=silver size=1> </h1> <h2><i>There is no row at position 0.</i> </h2> <p align=left></span><font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif "><b>Description: </b>An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and where it originated in the code. <br><br><b>Exception Details: </b>System.IndexOutOfRangeException: There is no row at position 0.<br><br><b>Source Error:</b> <br><br> <table width="100%" bgcolor="#ffffcc"> <tbody> <tr> <td><code>An unhandled exception was generated during the execution of the current web request. Information regarding the origin and location of the exception can be identified using the exception stack trace below.</code> </td></tr></tbody></table><br><b><font face=Verdana>Stack Trace:</font></b> <br><br> <table width="100%" bgcolor="#ffffcc"> <tbody> <tr> <td><code><pre>[IndexOutOfRangeException: There is no row at position 0.] System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg) +1734594 System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&amp; msgData, Int32 type) +826 Microsoft.FFSMC.Services.QuarantineManagement.GetQuarUserMachines(String strDomain, String strUser) +0 Microsoft.SEM.Services.LocalQuarantineManagement.GetQuarUserMachines(String strDomain, String strUser) +79 Microsoft.SEM.SEMConsole.AntQuarMgt.PopulateComboBox() +208 Microsoft.SEM.SEMConsole.AntQuarMgt.Page_Load(Object sender, EventArgs e) +3679 System.Web.UI.Control.OnLoad(EventArgs e) +99 System.Web.UI.Control.LoadRecursive() +47 System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint, Boolean includeStagesAfterAsyncPoint) +1061 </pre></code></td></tr></tbody></table><br></p> <hr width="100%" color=silver size=1> <p align=left><b><font face=Verdana>Version Information:</font></b> Microsoft .NET Framework Version:2.0.50727.832; ASP.NET Version:2.0.50727.832 </font></p>Thu, 08 May 2008 22:51:50 Z2009-08-03T21:06:04Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/ada5ebac-018c-4a54-a67e-a1b779f8c72ahttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/ada5ebac-018c-4a54-a67e-a1b779f8c72aNWranichhttp://social.technet.microsoft.com/Profile/en-US/?user=NWranichQuestion on deploying FSSMC<p>I was wondering what ports are used to allow traffic to flow between the FSSMC and remote servers.  My company has a servers running in separate domains that our main domain forest.  I would like to add these servers to the FSSMC and deploy the agent for reporting functions.  Where they are now, the FSSMC does not recognize the servers and I cannot add them to the FSSMC<br/><br/>Are there specific ports that the FSSMC uses when adding servers and/or deploying the agent?</p>Wed, 22 Jul 2009 19:37:57 Z2009-07-30T05:00:19Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/ebb94670-af6f-4b2f-806f-aa756fc1ff55http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/ebb94670-af6f-4b2f-806f-aa756fc1ff55John Senterhttp://social.technet.microsoft.com/Profile/en-US/?user=John%20SenterFSSMC update for Forefront for Exchange SP2Is there update for FSSMC that will have the added virus engines?  If not how do we get the update definitions to the Exchagne servers with the update job?Tue, 07 Jul 2009 15:50:06 Z2009-08-19T09:45:40Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/e73f5195-f062-473c-8ccb-1794994d234ehttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/e73f5195-f062-473c-8ccb-1794994d234eDiego Castellihttp://social.technet.microsoft.com/Profile/en-US/?user=Diego%20CastelliCannot deploy agents.. RPC server unavailable.Hi all, <br/>i cannot deploy agents... it tells me: &quot;RPC server unavailable&quot; in the FSSMC....<br/><br/>on te client in the windows firewall logs i don't have any &quot;DROP&quot; so all connections are accepted.<br/>i can see the shares from the FSSMC.<br/>Remote Registry service is started on the client server.<br/><br/><br/>What could it be?<br/><br/>Thanks in Advance.<br/><hr class="sig">Diego CastelliFri, 24 Jul 2009 09:13:50 Z2009-07-27T10:05:34Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/cffdb8e1-da84-4648-9a76-443a8413a6fehttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/cffdb8e1-da84-4648-9a76-443a8413a6feStuabroadhttp://social.technet.microsoft.com/Profile/en-US/?user=StuabroadEDGE Server Communication with ForefrontI will install an EDGE server in my DMZ and the Exchange 2007 Org will  be managed by FrontBridge for outside spam filtering and additionally Forefront for internal server and client security.  What i can't find is the port(s) used by EDGE to report back to the Forefront reporting/management console etc.  This must exist as it must be possible to view what the EDGE is doing via Forefront as it has an  agent installed.<br/> <br/> Any ideas?<br/> <br/> Thanks in advance.<br/>Thu, 23 Jul 2009 15:08:21 Z2009-07-23T15:08:21Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/3474b3d4-299d-411d-ba99-0730c1bf05cbhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/3474b3d4-299d-411d-ba99-0730c1bf05cbfreacehttp://social.technet.microsoft.com/Profile/en-US/?user=freaceMOM.Datawarehousing.DTSPackageGenerator.exe fails daily on schdule task and manual ones.I have been receiving this error on our Forefront sever for a couple of months now. I have tried ever solution out on the web and nothing seems to help. I have run MOM.Datawarehousing.DTSPackageGenerator.exe /latency:XX many times and not really sure if this is working anymore. If someone has cracked the code on this, could you please help? I have posted my eventlog property on this error.<br/><br/>Thanks in advance.<br/><br/><br/><br/><br/>Log Name:      Application<br/>Source:        MOM.Datawarehousing.DTSPackageGenerator.exe<br/>Date:          5/13/2009 1:49:21 PM<br/>Event ID:      1001<br/>Task Category: None<br/>Level:         Error<br/>Keywords:      Classic<br/>User:          N/A<br/>Computer:      FOREFRONTWH01.polk.edu<br/>Description:<br/>Step StepInvokeInnerPackage failed.<br/>Step Error Source: Microsoft OLE DB Provider for SQL Server<br/>Step Error Description: (1:SC_Inner_DTS_Package) SubStep 'DTSStep_ExecuteSQLTask_SC_EventFact_View_1_Insert' failed with the following error: <br/>Transaction (Process ID 79) was deadlocked on lock resources with another process and has been chosen as the deadlock victim. Rerun the transaction.<br/>Execution was canceled by user.<br/>Step Error Code: -2147220441<br/>Step Error Help File:<br/>Step Error Help Context ID:0<br/>Event Xml:<br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt;<br/>  &lt;System&gt;<br/>    &lt;Provider Name=&quot;MOM.Datawarehousing.DTSPackageGenerator.exe&quot; /&gt;<br/>    &lt;EventID Qualifiers=&quot;0&quot;&gt;1001&lt;/EventID&gt;<br/>    &lt;Level&gt;2&lt;/Level&gt;<br/>    &lt;Task&gt;0&lt;/Task&gt;<br/>    &lt;Keywords&gt;0x80000000000000&lt;/Keywords&gt;<br/>    &lt;TimeCreated SystemTime=&quot;2009-05-13T17:49:21.000Z&quot; /&gt;<br/>    &lt;EventRecordID&gt;29605&lt;/EventRecordID&gt;<br/>    &lt;Channel&gt;Application&lt;/Channel&gt;<br/>    &lt;Computer&gt;FOREFRONTWH01.polk.edu&lt;/Computer&gt;<br/>    &lt;Security /&gt;<br/>  &lt;/System&gt;<br/>  &lt;EventData&gt;<br/>    &lt;Data&gt;Step StepInvokeInnerPackage failed.<br/>Step Error Source: Microsoft OLE DB Provider for SQL Server<br/>Step Error Description: (1:SC_Inner_DTS_Package) SubStep 'DTSStep_ExecuteSQLTask_SC_EventFact_View_1_Insert' failed with the following error: <br/>Transaction (Process ID 79) was deadlocked on lock resources with another process and has been chosen as the deadlock victim. Rerun the transaction.<br/>Execution was canceled by user.<br/>Step Error Code: -2147220441<br/>Step Error Help File:<br/>Step Error Help Context ID:0&lt;/Data&gt;<br/>  &lt;/EventData&gt;<br/>&lt;/Event&gt;Wed, 13 May 2009 18:05:19 Z2009-07-02T08:12:13Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1d8634a5-c661-4237-a7fc-042b6be7fa41http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/1d8634a5-c661-4237-a7fc-042b6be7fa41Bob Ackerman MShttp://social.technet.microsoft.com/Profile/en-US/?user=Bob%20Ackerman%20MSBlock specific users from specific URLs in ISA 2004<p>Using ISA 2004 (Standard, shipped with SBS 2003 R2), I'd like to block specific users from specific Web sites. I can define URL sets, and create a rule with the default action of Deny that has the URL set as the To destination, and the URLs are blocked for all users. When I add a user set to the Users tab, as the Condition for the rule, the URLs are still blocked for all users not the specified user set. The From/Listener is the predefined Internal network.</p>Thu, 05 Mar 2009 06:17:44 Z2009-06-10T10:51:39Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d858ba6c-69b4-45e6-91a5-770a674c9225http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/d858ba6c-69b4-45e6-91a5-770a674c9225wilfried van ohttp://social.technet.microsoft.com/Profile/en-US/?user=wilfried%20van%20ofssmc exchange product activation job expires forefront for exchangeHi,<br><br>When I Create a Product Activation Job via FSSMC and fill in the required license key and the product license information and run the job agains the Exchange Servers I receive an error message when I conect with Forefront Security Admin for Exchange that the subscription has expired.<br><br>If I look at the about info in FSA then the subscription is expired on 26 oktober 1857 (if you deploy it a later time a different date is present).  <br><br>If I manually enter the information via FSA then everything works as expected.<br><br>FSSMC Exchange 2007 SP1 rollup 2<br>FSSA Exchange 2007 SP1 rollup 3<br><br>Anyone seen this before and has a fix for this?<br><br><br>Wed, 18 Mar 2009 13:43:39 Z2009-06-10T10:48:39Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f949f98f-2efd-49d9-a69e-0e87baa54749http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/f949f98f-2efd-49d9-a69e-0e87baa54749Erik802http://social.technet.microsoft.com/Profile/en-US/?user=Erik802Why can't I turn on Microsoft Forefront Client Security?When I go to Windows Security Center, only 3 out of 4 security essentials are turned on. Firewall, Automatic Updating, and Other security settings are always on, as well as Windows Defender under Spyware and malware protection. But my computer warns me that my virus protection, Microsoft Forefront Client Security, is turned off. When I click Turn on now, it leads me to a page that says no unwanted or harmful software detected. Is there a way to just turn it on and leave it on? If it says it's off can I get a virus?Sun, 22 Mar 2009 03:24:18 Z2009-06-10T10:43:03Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/449b7b0b-d4dd-4db6-a10a-721f8622482dhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/449b7b0b-d4dd-4db6-a10a-721f8622482dpsinehahttp://social.technet.microsoft.com/Profile/en-US/?user=psinehaHow to set ISA 2006 policy to communicate with APC powerchute network shutdown?I have Windows Server 2003 Ent R2 SP2 with ISA 2006 Ent.<br/>I will install APC 5000VA with NMC and PowerChute Network Shutdown on ISA 2006 server.<br/><br/>How can I set the ISA policy to communicate with APC that APC PCNS can shutdown ISA server?Wed, 20 May 2009 20:04:54 Z2009-06-10T10:35:27Zhttp://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/b0c1fde7-02bd-4902-a799-2f1239c161a5http://social.technet.microsoft.com/Forums/en-US/ForefrontserverMC/thread/b0c1fde7-02bd-4902-a799-2f1239c161a5Mohammed Shettihttp://social.technet.microsoft.com/Profile/en-US/?user=Mohammed%20ShettiForeFront Architecture Pushing Updates <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:small;font-family:Times New Roman">Which is better WSUS or SMS?</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:small;font-family:Times New Roman"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:small;font-family:Times New Roman">Regards,</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:small;font-family:Times New Roman">Mohammed </span></p>Sun, 24 May 2009 07:30:33 Z2009-06-10T10:12:46Z