Forefront Edge Security – IAG/UAG ForumA forum for the discussion of issues and ideas regarding IAG (Intelligent Application Gateway) and UAG (Unified Application Gateway)© 2009 Microsoft Corporation. All rights reserved.Wed, 25 Nov 2009 18:34:42 Zf987bccb-26e5-454d-8f69-09dda0a1cb59http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/da301a6b-609f-43f1-8f69-1220c29ae21bhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/da301a6b-609f-43f1-8f69-1220c29ae21bSteven Livingstone-Perezhttp://social.technet.microsoft.com/Profile/en-US/?user=Steven%20Livingstone-PerezLOGIN_FORM USER_NAME with a variable name/id?Here's a fun on. In my FormLogin.xml i need to match a form with a name (and ID) that actually varies every time the user refreshes the page (a GUID is added to the name). <div><br/></div> <div>I have no contol over this remote app.</div> <div><br/></div> <div>Anyone know of a way i can match it?</div> <div><br/></div> <div>I tried :</div> <div><br/></div> <div>&lt;NAME&gt;ctl00$PlaceHolderMain$Login1$LoginControlExtender1$*&lt;/NAME&gt;</div> <div><br/></div> <div>No success.</div> <div><br/></div> <div>thanks,</div> <div>steven</div> <div>http://livz.org</div> <div><br/></div> <div><br/></div>Wed, 25 Nov 2009 18:34:41 Z2009-11-25T18:34:42Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/96afc3ff-eec2-40ce-a5db-1950f444a4e4http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/96afc3ff-eec2-40ce-a5db-1950f444a4e4DarrenBonehillhttp://social.technet.microsoft.com/Profile/en-US/?user=DarrenBonehillIAG Network Connector and UAG SSTPI have a client in the education sector that would like to use the VPN functionality within IAG/UAG. As the client is in the educational sector they are looking at students connecting in and students may have Apple or Libux based machines. I understand that NC will not work on these machines. So I'll get to my question...... Will SSTP work for Linux / Apple to give end user the full VPN style connectivity.Tue, 24 Nov 2009 09:43:47 Z2009-11-25T16:42:44Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/6d4ac3b6-a68a-43dd-a243-26c4f006b12ehttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/6d4ac3b6-a68a-43dd-a243-26c4f006b12eErin Carterhttp://social.technet.microsoft.com/Profile/en-US/?user=Erin%20CarterCustom client app cannot connect to SQL server over Network ConnectorHi all,<br/><br/>We have a custom client application that connects to an SQL server on port 1134 for authenticating the user.<br/>This application is unable to communicate over the Network Connector, giving a network error.<br/><br/>Any suggestions on how to troubleshoot/fix this ?  I thought Network Connector should allow full access to internal IPs?<br/><br/>Using telnet commands I can verify the port is unavailable when NC is up.  NC access is testing ok for RDP, web etc.<br/>I also cannot ping the internal IP address from the client PC using network connector.<br/><br/>The IP address of the SQL server is included in a network entry on the &quot;Additional Networks&quot; tab of the Network Connector configuration on the whale/iag server.<br/><br/>Using telnet commands I can verify that I can connect to the port from the internal whale/iag server to the SQL server.<br/>I can ping the SQL server from the internal whale/iag server.  Our firewall admin has confirmed that all traffic from the internal whale/iag server is allowed.<br/><br/>I know we could publish the client app on Citrix but we'd rather get it working over NC.<br/><br/>Whale Version 3.6.1.0.55<br/>Service Pack 1.46<br/>Update 4.55Wed, 25 Nov 2009 14:30:39 Z2009-11-25T14:30:40Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/91a54568-d4cf-4a8b-ab68-d57464726d0fhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/91a54568-d4cf-4a8b-ab68-d57464726d0fSteven Livingstone-Perezhttp://social.technet.microsoft.com/Profile/en-US/?user=Steven%20Livingstone-PerezCoding a Custom Credential Store for Basic authentication or HTTP forms-based authentication Hi. I have looked at some articles discussing how you can write code to authenticate against your own authentication backend with IAG. <div><br/></div> <div>Now, when IAG intercepts and replays credentials for a given site - say Hotmail.com, I again want to write code that uses my own authentication store (long story) to pull out the credentials to be POSTed for that user (i.e. i don't have all my credentials in the IAG store).</div> <div><br/></div> <div>Does anyone know where i can get started?</div> <div><br/></div> <div>thanks,</div> <div>/steven</div> <div>http://livz.org</div>Tue, 27 Oct 2009 17:39:08 Z2009-11-24T21:08:42Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5031cefc-f864-48e1-a368-03965496dff3http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5031cefc-f864-48e1-a368-03965496dff3David Guesthttp://social.technet.microsoft.com/Profile/en-US/?user=David%20GuestHow can you perform Multiple Authentication Types within one IAGWe have an opportunity to replace a non-Microsoft reverse proxy with an IAG applicace.  However the current device allows for different authentication methods dependant on the resource being accessed.  As an example to get to the OWA the user has to use ID and Password but if they then move to a Finance application they also have to provide a Token (in this case Vasco).  I can see how to get all of the resources to be accessed with an ID and Password or using ID, Password and Token but I really need to provide an or in this.  That way all users can have the IAG security in front of OWA and they do not all need tokens.  When finance then need to access they get asked to provide the Token in addition to the current authentication.  I am not sure if thius can be done with multiple trunks but we need to keep the access URL's the same so that all users &quot;see&quot; the same thing.<br/><br/>Any ideas ???Tue, 24 Nov 2009 09:43:58 Z2009-11-24T16:19:29Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/02f34915-5695-4507-a259-43bf4ee9c526http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/02f34915-5695-4507-a259-43bf4ee9c526jcarlenhttp://social.technet.microsoft.com/Profile/en-US/?user=jcarlenUAG Direct Access and Citrix.<p class=MsoNormal style="margin:0cm 0cm 10pt"><span style="line-height:115%;font-family:'Verdana','sans-serif';color:black;font-size:8pt" lang=EN-US>We also have a Citrix farm where most of our applications are published. By using a Citrix secure gateway we were able to get citric working with Ipv 6 and the Direct Access server. But after upgrading the DA to a UAG It does not work anymore. We can access the webpage on the secure gateway but when we trying to kick an app we get an error saying that the ssl handshake failed error 40 (citrix error). My question is why does this not work on the UAG when it work's on a standard DA solution.<br/><br/>/Johan</span></p>Sun, 22 Nov 2009 21:27:11 Z2009-11-24T11:59:22Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/abb2ba24-cded-4bd4-9718-b32471653d32http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/abb2ba24-cded-4bd4-9718-b32471653d32Stefan.7http://social.technet.microsoft.com/Profile/en-US/?user=Stefan.7Issue publish webbased ERP with IAGHello,<br/><br/>we will publish our erp application with IAG. The welcome page works fine. The application url is <a href="http://servername/web/">http://servername/web/</a><br/>Form the IAG Portal the URL is <a href="https://....whalecom0/web/home/default.aspx">https://....whalecom0/web/home/default.aspx</a><br/><br/>On the left side is an navigation frame, which doesn't work.<br/>The current url ist <a href="https://...whalecom0/navigation/menu.aspx">https://...whalecom0/navigation/menu.aspx</a> --&gt; The page cannot be desplayed.<br/><a href="https://...whalecom0/web/navigation/menu.apsx">https://...whalecom0/web/navigation/menu.apsx</a> would be the correct url. The IAG ignore the rootfolder &quot;web&quot; of the webapplication and open the navigation-url directly after &quot;whalecom0&quot;. How can I resolve this issue? Tue, 24 Nov 2009 10:40:34 Z2009-11-24T10:40:35Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/a15b1a30-2c0b-452b-a381-b8da38d36c7bhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/a15b1a30-2c0b-452b-a381-b8da38d36c7bT.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.End-Point Compliance Warning?Hi,<br/><br/>Is there a way, without using NAP, that UAG can simply warn users when they are non-compliant - maybe some pop-up or something?<br/>(e.g. &quot;your anti-virus does not meet company requirements, and you will be granted access until 31 dec 2009, and each session will last 60 minutes. Contact helpdesk on 12345&quot;)<br/><br/>I assume this data would be available in the UAG log / report.<br/><br/>Regards,<br/>TZThu, 19 Nov 2009 16:20:08 Z2009-11-24T10:24:17Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/db6e2254-88ee-406c-85c6-2e9bcc83bc2ahttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/db6e2254-88ee-406c-85c6-2e9bcc83bc2aT.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.UAG array and NLB questionsHi,<br/><br/>According to the UAG IPD:<br/><br/>&quot;<span lang=EN-US><span style="font-family:Arial;font-size:x-small">Load balancing of incoming requests can be performed by either of the following:</span></span> <p class=BulletedList1 style="margin:3pt 0cm 3pt 18pt"><span style="font-family:Symbol" lang=EN-US><span><span style="font-size:x-small">·</span><span style="font:7pt 'Times New Roman'">         </span></span></span><span style="font-family:Arial"><span style="font-size:x-small"><strong><span lang=EN-US>Windows Network Load Balancing (NLB).</span></strong><span lang=EN-US> Up to eight Forefront UAG servers can be placed into an array to load balance VPN or DirectAccess traffic.</span></span></span></p> <p class=BulletedList1 style="margin:3pt 0cm 3pt 18pt"><span style="font-family:Symbol" lang=EN-US><span><span style="font-size:x-small">·</span><span style="font:7pt 'Times New Roman'">         </span></span></span><span style="font-size:x-small"><span style="font-family:Arial"><strong><span lang=EN-US>Hardware load balancer<span class=Bold><span style="font-family:'Arial', 'sans-serif'">.</span></span></span></strong><span lang=EN-US> A hardware load balancer is not supported for Forefront UAG when it is used to provide an array for DirectAccess.</span></span></span></p> <p class=Text style="margin:3pt 0cm"><span lang=EN-US><span style="font-family:Arial;font-size:x-small">Note that Forefront UAG is not supported in a Microsoft failover cluster.</span></span></p> <p class=Text style="margin:3pt 0cm"><span lang=EN-US><span style="font-family:Arial;font-size:x-small">No architectural guidance is available for determining the number of servers that will be required in the array. The array function is implemented by Forefront TMG, which is installed by the Forefront UAG installer. The array members share the same configuration and provide the same set of services. If an array node fails, services can be accessed from another array member. One of the array members is configured as the array manager and holds the configuration for the entire array. </span></span></p> <p class=Text style="margin:3pt 0cm"><span lang=EN-US><span style="font-family:Arial;font-size:x-small">To deploy multiple Forefront UAG servers in an array, all the servers must be domain members.&quot;<br/></span></span></p> <p class=BulletedList1 style="text-indent:0cm;margin:3pt 0cm;tab-stops:36.0pt"><span lang=EN-US><span style="font-family:Arial;font-size:x-small"><br/>A few questions:<br/>1. &quot;The array function is implemented by Forefront TMG&quot; so there is no separate UAG array concept? I can only think of a manual reconfiguration option here.<br/>2. In order to have a UAG array, do I need the Standard or Enterprise Edition of TMG? I guess that is covered by the UAG license agreement? Do I need to purchase different UAG/TMG combo then?<br/>3. The IPD states: &quot;<span lang=EN-US><span style="font-family:Arial;font-size:x-small">To deploy multiple Forefront UAG servers in an array, all the servers must be domain members&quot; - is there a way to achieve a UAG array concept, without domain membership? Probably not.<br/>4. Can I assume that if I do not utilise DirectAccess, I can still use a hardware load balancer for UAG?<br/><br/>Thank you,<br/>TZ</span></span></span></span></p>Thu, 19 Nov 2009 07:37:05 Z2009-11-24T10:23:02Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/13acb762-76e3-4fce-93c1-d57f751ad43dhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/13acb762-76e3-4fce-93c1-d57f751ad43djforgesonhttp://social.technet.microsoft.com/Profile/en-US/?user=jforgesonUAG DirectAccess Wildcard CertificateHi all,<br/>Just having a small issue with UAG DirectAccess and a wildcard SSL certificate for the IP-HTTPS certificate.<br/>As the wildcard certificate has a * in the subject name it is not accepted by the UAG DirectAccess setup and returns the following error.<br/><br/>&quot;The selected certificate CN=*.example.com does not have a suitable subject name. Select a certificate with a valid FQDN as a subject name.<br/><br/>Does this mean that we cannot use our wildcard certificate for UAG DirectAccess?Tue, 17 Nov 2009 19:44:02 Z2009-11-24T06:04:08Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/b7fe5852-d98e-40b0-bd97-83e8067428f6http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/b7fe5852-d98e-40b0-bd97-83e8067428f6thmoore0820http://social.technet.microsoft.com/Profile/en-US/?user=thmoore0820How to configure IAG with RD Gateway using RPC over HTTPSWe are looking for configuration guidance on how to configure IAG 2007 SP1 or SP2 to communicate to Remote Desktop Services Gateway running on Windows Server 2008 R2 using the 3389 RPC over HTTPS feature. I can not find any configuration guide for this since the release of R2. To be specific we are trying to configure IAG to talk to a Remote Desktop Gateway with HTTPS on 443, the more secure approach which is one of the new features of the R2 release of Remote Desktop Gateway (formerly Terminal Services Gateway).Wed, 18 Nov 2009 22:30:46 Z2009-11-23T23:17:46Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/2af2fc7b-2564-45d8-aa63-9bb2f67315f4http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/2af2fc7b-2564-45d8-aa63-9bb2f67315f4Steven Livingstone-Perezhttp://social.technet.microsoft.com/Profile/en-US/?user=Steven%20Livingstone-PerezIAG with OpenID credential capture and replayI know IAG can capture and replay basic authentication and forms authentication. <div><br/></div> <div>Anyone know if IAG can capture and replay OpenID authentication?</div> <div><br/></div> <div>thanks,</div> <div>steven</div>Mon, 16 Nov 2009 11:16:51 Z2009-11-23T23:10:34Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/b314b294-d0a9-475a-b900-14734f453961http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/b314b294-d0a9-475a-b900-14734f453961sigjashttp://social.technet.microsoft.com/Profile/en-US/?user=sigjasUAG R0 TS WEB ClientHi, when adding the TS Web client to the portal, the path is /tsweb/. I am using windows 2008 terminal services, and the path is /ts/. I have tried changing this in the applications properites for the Web client, but I still get an error.<br/><br/>jasonFri, 23 Oct 2009 19:17:18 Z2009-11-23T18:15:12Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/2ef410fd-8715-4465-93b9-bdb8b4f44e98http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/2ef410fd-8715-4465-93b9-bdb8b4f44e98DarrenBonehillhttp://social.technet.microsoft.com/Profile/en-US/?user=DarrenBonehillRDP Connectivity from Netbook With XP Home EditionI have a client running a NetBook with XP Home addition. When connecting through IAG we are unable to connect to an RDP session and see the error  &quot;Failed to connect to Server ......&quot; This work from other clients but not from the Net Book. Anybody got any ideas ?Wed, 11 Nov 2009 09:21:35 Z2009-11-23T10:14:14Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/54292228-e3cb-46ec-9378-e47b0e190e90http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/54292228-e3cb-46ec-9378-e47b0e190e90T.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.UAG Portal & TS RemoteAppHi,<br/><br/>We are thinking of using the TS Remote App and using the TS Web concept - for access to non-web applications.<br/>This TS Web can obviously be published via UAG.<br/><br/>However, when you first connect to UAG, you may have a few application icons on the portal page, and one being the link to the TS Web Remote App.<br/>This second list of application may actually confuse some users.<br/><br/>So - is there a way of publishing those TS Remote Apps so that their shortcut icons appear directly in the UAG portal page?<br/><br/>Regards,<br/>TZ<br/><br/>PS. Does someone know if there is another version of this site: <a href="http://www.iagserver.org/default.aspx?ctype=Articles&amp;&amp;name=How-to-install-and-configure-TS-RemoteApp-and-TS-Web-Access-and-Publish-through-Microsoft-Intelligent-Application-Gateway-(IAG)-2007-Server">http://www.iagserver.org/default.aspx?ctype=Articles&amp;&amp;name=How-to-install-and-configure-TS-RemoteApp-and-TS-Web-Access-and-Publish-through-Microsoft-Intelligent-Application-Gateway-(IAG)-2007-Server</a><br/><br/>There are many people that seem not to be able to view it, us included.Wed, 18 Nov 2009 19:44:07 Z2009-11-23T08:12:08Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/fac981d8-1473-4d05-a319-c93242d0fb88http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/fac981d8-1473-4d05-a319-c93242d0fb88dwthomahttp://social.technet.microsoft.com/Profile/en-US/?user=dwthomaWindows 7 x64 - Remote Desktop UAG RC0I have a windows 7 x64 desktop and im trying to connect to a remote desktop option that i configured on the applications list in the UAG portal (UAG RC0). <br/>I keep getting the error 'your computer does not meet the security policy requirements for this application'. I have enabled endpoint policy settings to 'always' for this application. <br/><br/>for testing i just want it to bypass all security settings. i used the debug option and found it made no difference even though it says its going disable security. <br/><br/>Where can i go to debug this security message?<br/><br/><hr class="sig">dwethomaMon, 23 Nov 2009 04:48:59 Z2009-11-23T04:48:59Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/50560536-6be5-4e2e-ab60-79543d35ecfbhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/50560536-6be5-4e2e-ab60-79543d35ecfbMustakihttp://social.technet.microsoft.com/Profile/en-US/?user=Mustakicertificate login and user status in AD<p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-family:'Verdana','sans-serif';color:black;font-size:8pt">Hi all,<br/>after implementing certificate login with IAG2007 I have realized that disabled users can still access the portal after they have been disabled in AD.<br/>I have been told that the IAG function getuserinformation may do the trick of checking the user status. can someone help with this as I have no programming skills.<br/>any information, perhaps working code would be highly appreciated.<br/>cheers,<br/>tom</span></p> <br/>Sun, 22 Nov 2009 09:28:33 Z2009-11-22T09:28:34Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5fa65531-ab41-4e34-9181-c168fc21aa68http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5fa65531-ab41-4e34-9181-c168fc21aa68T.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.SSL Accelerators & UAGHi,<br/><br/>I have read this post regrding planning for a large number of concurrent users and IAG and SSL impact: <a href="http://forums.forefrontsecurity.org/default.aspx?g=posts&amp;m=808">http://forums.forefrontsecurity.org/default.aspx?g=posts&amp;m=808</a><br/>Will this still apply to UAG?<br/><br/>We were thinking of, instead of an appliance, of getting a SSL Accelerator card and sticking it in the hyper-v machine running UAG...but will this limitation still apply?<br/><br/>&quot;SSL accelerator network card is working with dedicated network driver but in Hyper-V you have the virtual network driver netvsc50.dll and you cannot replace it<br/>So ... you only option is to use external SSL accelerator hardware solution&quot;<br/><br/>So, does this mean that one should rather look at UAG appliances for large number of concurrent users over SSL? Are there any guidelines available - when to start using appliances vs hyper-v images?<br/><br/>I assume similar questions could be asked about NLB. UAG now has NLB support - but at which point do you switch over to a hardware solution (like F5 for instance?)<br/><br/>Kind regards,<br/>TZThu, 19 Nov 2009 05:43:12 Z2009-11-23T18:11:58Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/74d12bd0-aec7-44a4-9d9f-9348f9e38931http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/74d12bd0-aec7-44a4-9d9f-9348f9e38931T.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.802.1q Support?Hi,<br/><br/>Just curious whether UAG or TMG supports 802.1q (VLAN tagging)?<br/><br/>Regards,<br/>TZWed, 18 Nov 2009 17:45:32 Z2009-11-23T18:11:34Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/d22fdb94-0ff3-45a5-8b91-f8fde89c1743http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/d22fdb94-0ff3-45a5-8b91-f8fde89c1743T.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.IAG HAT & Address RewriteHi,<br/><br/>For security reasons IAG rewrites the URL address and hides the internal URLs.<br/><br/>However, lets assume that I wish to publish Public websites via IAG - but do not wish to do the address rewrite...so <a href="http://company.com">http://company.com</a> always appears as http://company.com.<br/><br/>Is that possible?<br/><br/>Thanks,<br/>TTue, 17 Nov 2009 17:23:29 Z2009-11-18T17:43:09Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/dac3fb3b-ea1e-4a0b-a23d-ed66d5602673http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/dac3fb3b-ea1e-4a0b-a23d-ed66d5602673T.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.IAG & non-web applicationsHi,<br/><br/>Just trying to understand the technicalities behind IAG &amp; publishing non-web apps.<br/><br/>Lets assume I have a home grown client/server app.<br/>People on the intranet need the client portion installed on their desktops, and this connects to the backend server component on the intranet.<br/><br/>If I now want to publish this via IAG, how do I actually go about it?<br/>Lets say I want to allow access to this client/server app to clients outside my network, that do not have the client portion installed on their desktops.<br/><br/>How do I use IAG for this?<br/><br/>The only way I can think of right noe is to setup a Terminal Server App Mode and install the client portion of the home grown app on it.<br/>Then publish that thru IAG, maybe on a TS Web page.<br/><br/>Is that the right thinking, or did the IAG team have another solution in mind?<br/><br/>Thanks,<br/>TWed, 18 Nov 2009 05:40:56 Z2009-11-18T18:42:28Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/3bdf6533-9a2a-427f-94d0-cc2490f19591http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/3bdf6533-9a2a-427f-94d0-cc2490f19591T.Z.http://social.technet.microsoft.com/Profile/en-US/?user=T.Z.IAG DMZ Design ideas/questionsHi,<br/><br/>We have the following requirement:<br/>- Internal corporate staff need to access application (web &amp; non-web) that reside on the intranet &amp; DMZ<br/>- External partners need to access application (web &amp; non-web) that reside on the intranet &amp; DMZ<br/><br/>We will use IAG/UAG for most of the application access and publishing.<br/><br/>So I am suggesting 2 separate forests (internal staff &amp; external partners) and a 2-way (selective authentication) trust between them.<br/><br/>I am then thinking of placing both these forests on the intranet. (as opposed to placing the external partners AD in the DMZ) - whats the best practice here?<br/>Since some of the front-end Sharepoint components and IAG itself will reside in the DMZ, will there be any benefit of deploying RODCs to the DMZ from either forest?<br/><br/>Any pointers, thoughts, url's welcome.<br/><br/>Thank you,<br/>TMon, 16 Nov 2009 20:06:53 Z2009-11-23T18:11:24Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/290e54f0-d46a-41eb-b00a-fa8d9bab777ehttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/290e54f0-d46a-41eb-b00a-fa8d9bab777eBill Hankshttp://social.technet.microsoft.com/Profile/en-US/?user=Bill%20HanksNetwork Connector ErrorHello All, <div><br/></div> <div>I am facing a issue with the network connector. If i activate the network connector and publish it on one of the trunk than the all the published trunk stops to work.And as soon as we disable the network connector than all the published portals starts to work. Anybody has an any idea as to why this is happening.</div> <div><br/></div> <div><br/></div> <div><br/></div><hr class="sig">Cheers BillFri, 13 Nov 2009 12:33:36 Z2009-11-17T12:57:04Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/9a4c45fe-a780-4e07-85a9-93b9aa6cf651http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/9a4c45fe-a780-4e07-85a9-93b9aa6cf651Bob Elwardhttp://social.technet.microsoft.com/Profile/en-US/?user=Bob%20ElwardIAG Support For Windows 7We are currently running IAG.  We are running a limited number of Windows 7 RC devices and would like to know if Windows 7 will be supported in the current release of IAG?  It's our assumption that Windows 7 will RTM months before UAG w/ support for Windows 7 RTMs.Tue, 21 Jul 2009 19:57:58 Z2009-11-16T20:06:29Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/997613cc-558c-41f9-ae92-c4ef16e5f675http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/997613cc-558c-41f9-ae92-c4ef16e5f675AdrianOConnorhttp://social.technet.microsoft.com/Profile/en-US/?user=AdrianOConnor UAG RC0 Home Drive QuestionHi Guys,<br/><br/><strong>Server Details</strong><br/><em>Forefront Unified Access Gateway (UAG) RC0 Server,<br/>Domain Member,<br/>Two NICs, One Internal, One External (Portal.Mydomain.Com)</em><br/><br/><br/>We have a Trunk up and running with a Portal containing a number of Websites. We can log on successfully and browse all the Internal Websites, some which require a username \ password and some which dont.<br/>All working fine.<br/><br/><br/>My Authentication Settings are as follows;<br/><br/><em><strong>Under Authentication Settings</strong><br/>Server Type: ACTIVE DIRECTORY<br/>Server Name: AD<br/><br/><strong>Define Domain Controllers</strong><br/>IP Address/host: CAD1.mydomain.com 389 <br/>IP Address/host: CAD2.mydomain.com 389 <br/><br/><strong>Search settings</strong><br/>Base DN: DC=Mydomain,DV=com<br/>Include Subfolders: Ticked<br/>Level of Nested groups: 6<br/><br/><strong>Server Access</strong><br/>User: (NetBios Name)\Username : CAD\UAG_User<br/><br/><strong>Default domain name</strong><br/>Domain: Netbios Name : CAD</em><br/><br/><br/>When I try and configure FILE ACCESS to allow access to Home Directorys. I log in using my Domain Admin accound and try and configure the following<br/><br/><em><strong>Home Directory</strong><br/>Use Domain Controller Settings for Home Directories<br/><br/><strong>Mapped Drives</strong><br/>Show Mapped Drives: Ticked<br/><br/><strong>Share Permissions</strong><br/>Show only the shares a user is permitted to access: Ticked</em><br/><br/><br/>However when I then try and click on File Access\File Access Admin\Network Sharing\Domains<br/>I get the following Error<br/><br/><strong>Failed to Enumerate domains<br/>Please Check your permissions.<br/></strong><br/><br/>Any Ideas?<br/>Tue, 10 Nov 2009 15:18:43 Z2009-11-16T16:22:00Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/63d4b5f3-f9dc-4c2c-81c5-e91d36536ec3http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/63d4b5f3-f9dc-4c2c-81c5-e91d36536ec3sigjashttp://social.technet.microsoft.com/Profile/en-US/?user=sigjasUAG file access home drive<p>Hi, I have UAG installed on a windows 2008 r2 server. It is a domain member of a 2008 domain.&nbsp; I have a internal/external interface on the uag server. I have enabled file access&nbsp; "use domai controller settings for home directories". I have confirmed the home drive share by logging into the domain with a client (windows xp) computer.</p> <p>When I logon to the portal I do not see a home drive. I only get 'file access' 'network'.<br /><br />Is there anyway I can enable tracing or verbose debugging? <br /><br />Any suggestions appreciated.<br />jason</p> <p>&nbsp;</p> <p>&nbsp;</p>Tue, 06 Oct 2009 20:31:56 Z2009-11-16T14:14:25Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/6c2b72a1-bda2-47fc-8f78-8d79dc1ce2cahttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/6c2b72a1-bda2-47fc-8f78-8d79dc1ce2caNórihttp://social.technet.microsoft.com/Profile/en-US/?user=N%u00f3riIPSec Audit Failures when using Forefront UAG DirectAccessI've installed Forefront UAG DirectAcess and I'm not getting it to work properly. I read the planning and deployment guides and believe I have configured everything according to those. I'm not using IPv6 on our intranet. I'm able to ping all servers but that's it. I have no other access to them.<br/><br/>On the clients I'm getting the following two Audit Failures in the Security log:<br/><br/> <pre lang=x-xml>An IPsec main mode negotiation failed. Local Endpoint: Local Principal Name: - Network Address: 2002:d5b0:91a5:8100:19a1:7094:9919:3984 Keying Module Port: 500 Remote Endpoint: Principal Name: - Network Address: 2002:d5b0:91a5::d5b0:91a5 Keying Module Port: 500 Additional Information: Keying Module Name: IKEv1 Authentication Method: Unknown authentication Role: Initiator Impersonation State: Not enabled Main Mode Filter ID: 0 Failure Information: Failure Point: Local computer Failure Reason: No policy configured State: No state Initiator Cookie: f88b2ecea742155c Responder Cookie: 0000000000000000</pre> <pre lang=x-xml>An IPsec extended mode negotiation failed. The corresponding main mode security association has been deleted. Local Endpoint: Principal Name: ANNATA\nori Network Address: 2002:d5b0:91a5:8100:19a1:7094:9919:3984 Keying Module Port: 500 Remote Endpoint: Principal Name: host/zanzan.annata.is Network Address: 2002:d5b0:91a5::d5b0:91a5 Keying Module Port: 500 Additional Information: Keying Module Name: AuthIP Authentication Method: Kerberos Role: Initiator Impersonation State: Enabled Quick Mode Filter ID: 67673 Failure Information: Failure Point: Local computer Failure Reason: IKE authentication credentials are unacceptable State: Sent second (SSPI) payload</pre> I've looked at the certificates and as far I can tell they are configured according to the prerequisites. There are two configured CRL distribution points. One LDAP and one publicly accessible.<br/><br/>Has anyone seen this behavior?<br/><br/>Kveðja,<br/>NóriTue, 10 Nov 2009 22:50:10 Z2009-11-16T17:51:14Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/e2ead7ee-809c-4257-a61b-854199916c52http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/e2ead7ee-809c-4257-a61b-854199916c52Louis Yunghttp://social.technet.microsoft.com/Profile/en-US/?user=Louis%20YungIAG, ActiveSync (E2K7 SP1) and Nokia Mail for ExchangeHas anyone had any experience with Nokia Mail for Exchange and ActiveSync through an IAG SP1 appliance? Our client has an HTTPS ActiveSync trunk which works fine for WM devices but fails for Nokias running Mail for Exchange or RoadSync. We've tested Mail for Exchange against another E2K7 server which is firewalled but not behind IAG and it syncs fine. These are the IIS logs from the Exchange CAS server:<br/> <br/> 1. Successful Mail for Exchange sync on E2K7, no IAG<br/> <br/> <pre>OPTIONS /Microsoft-Server-ActiveSync/default.eas User=user1&amp;DeviceId=IMEI351879013504065&amp;DeviceType=IMEI351879013504065&amp;Log=V10_LdapC0_LdapL0_RpcC0_RpcL0_ 443 domain1\user1 212.183.134.130 NokiaE61i/2.09(158)MailforExchange 200 0 0 POST /Microsoft-Server-ActiveSync/default.eas User=user1&amp;DeviceId=IMEI351879013504065&amp;DeviceType=IMEI351879013504065&amp;Cmd=Settings&amp;Log=V121_Ssnf:T_LdapC3_LdapL16_RpcC23_RpcL46_Ers1_Pk0_Error:DeviceNotProvisioned_ 443 domain1\user1 212.183.134.130 NokiaE61i/2.09(158)MailforExchange 449 0 0 POST /Microsoft-Server-ActiveSync/default.eas User=user1&amp;DeviceId=IMEI351879013504065&amp;DeviceType=IMEI351879013504065&amp;Cmd=Provision&amp;Log=V121_LdapC0_LdapL0_RpcC10_RpcL15_Pk0_S1_ 443 domain1\user1 212.183.134.130 NokiaE61i/2.09(158)MailforExchange 200 0 0 POST /Microsoft-Server-ActiveSync/default.eas User=user1&amp;DeviceId=IMEI351879013504065&amp;DeviceType=IMEI351879013504065&amp;Cmd=Provision&amp;Log=V121_LdapC0_LdapL0_RpcC11_RpcL0_Pk1623791423_Pa1_S1_ 443 domain1\user1 212.183.134.130 NokiaE61i/2.09(158)MailforExchange 200 0 0 POST /Microsoft-Server-ActiveSync/default.eas User=user1&amp;DeviceId=IMEI351879013504065&amp;DeviceType=IMEI351879013504065&amp;Cmd=Settings&amp;Log=V121_LdapC0_LdapL0_RpcC12_RpcL0_Pk1314988479_DevModel:NokiaE61i_DevIMEI:IMEI351879013504065_DevName:Nokia%2fMail+For+Exchange_DevOS:.0633.65.01_ 443 domain1\user1 212.183.134.130 NokiaE61i/2.09(158)MailforExchange 200 0 0 POST /Microsoft-Server-ActiveSync/default.eas User=user1&amp;DeviceId=IMEI351879013504065&amp;DeviceType=IMEI351879013504065&amp;Cmd=FolderSync&amp;Log=V121_St:F_Srv:22a0c0d0s0e0r_LdapC0_LdapL0_RpcC72_RpcL46_Pk1314988479_ 443 domain1\user1 212.183.134.130 NokiaE61i/2.09(158)MailforExchange 200 0 0 POST /Microsoft-Server-ActiveSync/default.eas User=user1&amp;DeviceId=IMEI351879013504065&amp;DeviceType=IMEI351879013504065&amp;Cmd=Sync&amp;Log=V121_Sk:0_LdapC0_LdapL0_RpcC22_RpcL15_Pk1314988479_S8_ 443 domain1\user1 212.183.134.130 NokiaE61i/2.09(158)MailforExchange 200 0 0</pre> <br/> 2. Successful WM sync on E2K7, IAG in place<br/> <br/> <pre>OPTIONS /Microsoft-Server-ActiveSync/default.eas User=user2&amp;DeviceId=48213A9049BC18642293876E5D8680AF&amp;DeviceType=SmartPhone&amp;Log=V120_LdapC0_LdapL0_RpcC0_RpcL0_Pk1080181950_ 443 domain2\user2 34.105.248.4 MSFT-SPhone/5.2.402 200 0 0 218 POST /Microsoft-Server-ActiveSync/default.eas User=user2&amp;DeviceId=48213A9049BC18642293876E5D8680AF&amp;DeviceType=SmartPhone&amp;Cmd=FolderSync&amp;Log=V120_St:S_LdapC0_LdapL0_RpcC15_RpcL78_Pk1080181950_ 443 domain2\user2 34.105.248.4 MSFT-SPhone/5.2.402 200 0 0 453 POST /Microsoft-Server-ActiveSync/default.eas User=user2&amp;DeviceId=48213A9049BC18642293876E5D8680AF&amp;DeviceType=SmartPhone&amp;Cmd=GetItemEstimate&amp;Log=V120_Fc3_Fid:40d1ced297368646b2ccb1bedbff9649-65278ae_Sk:2_Sst3_Pfs1_Fid:40d1ced297368646b2ccb1bedbff9649-65278ad_Sk:2_Sst11_Pfs1_Fid:40d1ced297368646b2ccb1bedbff9649-652ac30_Sk:47_Sst12_Pfs1_LdapC0_LdapL0_RpcC31_RpcL218_Pk1080181950_S1_ 443 domain2\user2 34.105.248.4 MSFT-SPhone/5.2.402 200 0 0 625 POST /Microsoft-Server-ActiveSync/default.eas User=user2&amp;DeviceId=48213A9049BC18642293876E5D8680AF&amp;DeviceType=SmartPhone&amp;Cmd=Sync&amp;Log=V120_Fc1_Fid:40d1ced297368646b2ccb1bedbff9649-65278ad_Ty:Ca_Filt4_St:S_Sk:2_Sst11_Srv:0a0c0d4s0e0r_LdapC0_LdapL0_RpcC17_RpcL15_Pk1080181950_S1_ 443 domain2\user2 34.105.248.4 MSFT-SPhone/5.2.402 200 0 0 406 POST /Microsoft-Server-ActiveSync/default.eas User=user2&amp;DeviceId=48213A9049BC18642293876E5D8680AF&amp;DeviceType=SmartPhone&amp;Cmd=Sync&amp;Log=V120_Fc1_Fid:40d1ced297368646b2ccb1bedbff9649-652ac30_Ty:Em_Filt3_St:S_Sk:47_Sst12_Srv:0a0c0d28s0e0r_LdapC0_LdapL0_RpcC24_RpcL46_Pk1080181950_S1_ 443 domain2\user2 34.105.248.4 MSFT-SPhone/5.2.402 200 0 0 250 POST /Microsoft-Server-ActiveSync/default.eas User=user2&amp;DeviceId=48213A9049BC18642293876E5D8680AF&amp;DeviceType=SmartPhone&amp;Cmd=Settings&amp;Log=V120_LdapC0_LdapL0_RpcC10_RpcL0_Pk1080181950_UserInfo:Get_ 443 domain2\user2 34.105.248.4 MSFT-SPhone/5.2.402 200 0 0 390 </pre> <br/> 3. Unsuccessful Mail for Exchange sync on E2K7, IAG in place<br/> <br/> <pre>OPTIONS /Microsoft-Server-ActiveSync/default.eas &amp;Log=V20_LdapC1_LdapL0_RpcC0_RpcL0_ 443 domain2\user3 34.105.248.4 RoadSync-S60/4.0 200 0 0 187 POST /Microsoft-Server-ActiveSync/default.eas &amp;Log= 443 domain2\user3 34.105.248.4 RoadSync-S60/4.0 501 0 0 0 </pre> <br/> 4. Unsuccessful RoadSync sync on E2K7, IAG in place<br/> <br/> <pre>OPTIONS /Microsoft-Server-ActiveSync/default.eas &amp;Log=V10_LdapC0_LdapL0_RpcC0_RpcL0_ 443 domain2\user3 34.105.248.4 NokiaE61i/2.09(158)MailforExchange 200 0 0 218 POST /Microsoft-Server-ActiveSync/default.eas &amp;Log= 443 domain2\user3 34.105.248.4 NokiaE61i/2.09(158)MailforExchange 501 0 0 15 </pre> <br/> As you can see, the unsuccessful syncs are missing the &quot;User=&quot;, &quot;DeviceID=&quot;, &quot;DeviceType=&quot; and the start of the &quot;Cmd=&quot; sections. This returns a 501 not implemented error on the Nokia.<br/> <br/> My IAG troubleshooting knowledge is limited - I've been on an administrators course but it didn't really cover this kind of in depth troubleshooting of IAG itself. If anyone can point me in the right direction, that would be great. Unfortunately for us, the client has most of their execs on Nokias which means the issue is getting lots of attention :(<br/> <br/> Thanks in advance,<br/> <br/> Louis Yung<br/>Thu, 17 Sep 2009 14:37:10 Z2009-11-13T22:59:01Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/a7ca54cc-60e7-467a-961c-fc4b32151249http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/a7ca54cc-60e7-467a-961c-fc4b32151249schmidti83http://social.technet.microsoft.com/Profile/en-US/?user=schmidti83Windows 7 & IAG (Whale Client Components)Hi,<br/><br/><span lang=DE> <p>as a Microsoft and Windows Enthusiast i have testet Windows 7 Beta and now the RC!</p> <p>On a &quot;normal way&quot; i don´t get the Whale Client Compents and the Network Connector not installed. Now i have a workaround not a solution because this method and IAG/Whale Client Components are not offical supportet from Microsoft under Windows 7.<br/>I hope i can help other IAG users and the hole community with this.</p> <p>Her is the Workaround that works for me under <strong>Windows 7 (x86</strong>):<br/>- <strong>Locate the Directory &quot;OfflineClientSetup</strong>&quot; from the IAG-SP2 and <strong>extract</strong> the Complete OfflineClientSetup Diretory <strong>for example to c:\temp.</strong><br/>- browse to Whale Client Components &quot;<strong>Setup.exe&quot; and set the compatibility mode to &quot;Windows Vista SP2</strong>&quot;<br/>- browse to &quot;<strong>ClientCompoents.xml&quot; locate the entry for the Network Connector set it to &quot;1</strong>″ <br/>- now start the installation of the Whale Client Components with the &quot;Setup.exe&quot; (as Administrator)<br/>- Your can use normal or custom setup and start the installation (Attention: at the end of the setup the is a <strong>failure you can ignore &quot;Can not register Whale Client Components whlvaw.dll</strong>&quot;) - end the Setup<br/>- <strong>start cmd oder PowerShell as administrator (!)</strong> and switch to the path  &quot;<strong>C:\Program Files\Whale Communications\Client Components\3.1.0</strong>″<br/>- <strong>execute the command: &quot;regsvr32 whlvaw.dll&quot;</strong> (Attention: <strong>Ignore the Warning about the Driver isntallation and select YES</strong>!<br/>- Now you you your IAG Portal to login and start the Network Connector! But this only successful if you<strong> start the Internet Explorer as a Administrator</strong>, because the file &quot;whlioc.exe&quot; &amp; &quot;whliocsv.exe&quot; would launched with local administrator rights!<br/><br/>I hope this helps the hole community out the, who test Windows 7, because <strong>WINDOWS 7 ROCKZ!<br/></strong></p> </span>Screenshots: <a href="http://cid-966b26a11278266e.skydrive.live.com/browse.aspx/Windows 7 IAG Client Components">http://cid-966b26a11278266e.skydrive.live.com/browse.aspx/Windows%207%20IAG%20Client%20Components</a><br/><br/> <hr class=sig> Greetz JoergMon, 18 May 2009 09:39:19 Z2009-11-13T22:41:51Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/dbea2f4e-05ce-41ce-be32-86f4bca1f5e9http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/dbea2f4e-05ce-41ce-be32-86f4bca1f5e9The SCE Group - Bryanhttp://social.technet.microsoft.com/Profile/en-US/?user=The%20SCE%20Group%20-%20BryanCustom Endpoint Detection QuestionI have written quite a few custom endpoint detection scripts and I think it's about time we all understand some parts of this. When you create the &quot;PolicyTemplate.xml&quot; file in the customupdate folder, you have to create your custom variable. Well, in looking through the stock PolicyTemplate.xml file, there seem to be different values used for different things. Here's the XML structure that you need to utilize: <div>&lt;policy&gt;</div> <div>&lt;Name&gt;&lt;/Name&gt; - Obvioulsy, the name of the variable</div> <div>&lt;ID&gt;&lt;/ID&gt; - The variable you are using to record the results of whatever check in your script. </div> <div>&lt;Type&gt;&lt;/Type&gt; - I have no idea here, anyone? It seems to take a numeric value, but does anyone know what the types are and what values they map to?</div> <div>&lt;Value&gt;&lt;/Value&gt; - Is this the initial value of the variable? Is this how variable is determined? In some, I see &quot;false&quot;, but in others I see scripting. </div> <div>&lt;Description&gt;&lt;/Description&gt; - A description of your variable.</div> <div>&lt;Section&gt;&lt;/Section&gt; - The section in the UI that you want it to appear. </div> <div>&lt;Flags&gt;&lt;/Flags&gt; - Again, no idea here. It seems that this is optional, but when I do see it, I see a value of &quot;6&quot;. What is this field used for and what does 6 mean? </div> <div>&lt;/policy&gt;<br/><br/></div> <div>Thanks!</div>Wed, 11 Nov 2009 17:47:27 Z2009-11-13T18:28:39Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/d94e0cdf-9a56-48a5-9250-191efd790522http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/d94e0cdf-9a56-48a5-9250-191efd790522mdriscollhttp://social.technet.microsoft.com/Profile/en-US/?user=mdriscollUAG DirectAccess and RDPI've setup UAG RC0 and gone through the DirectAccess configuration. I have a client using Teredo. It connects to the UAG server and is able to ping resources on the Intranet, however, I am unable to browse to UNC paths or use RDP. Does anyone have any troubleshooting advice?Fri, 06 Nov 2009 22:39:07 Z2009-11-14T19:13:51Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/87ff2102-014c-4814-8d32-0956a413dd15http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/87ff2102-014c-4814-8d32-0956a413dd15DarrenBonehillhttp://social.technet.microsoft.com/Profile/en-US/?user=DarrenBonehillNetwork Connector Troubleshootig<p>I have posted the problem we are seeing at a customer site when using Network Connector across 3G.<br/><br/>We have setup logging on the Network Connector but I would like to setup some tracing / logging on the actual portal would anybody be able to assist in how I could set this logging up.<br/><br/>I have found how to setup the IIS logging but that doesn't seem to have the information I'm after.<br/><br/>I'm trying to see if I can capture why the NC is just stopping is it down to a timeout and the IAG applianced is sending the terminate commend or is it on the client side that the terminate comes from.<br/><br/>Anybody got any ideas ?</p>Thu, 12 Nov 2009 14:10:56 Z2009-11-13T16:24:17Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/eb83deb7-4524-40aa-baac-8392e82b4d6dhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/eb83deb7-4524-40aa-baac-8392e82b4d6dmattiboombalattihttp://social.technet.microsoft.com/Profile/en-US/?user=mattiboombalattiUAG Installation Failures On Server 2008 R2What am I missing here folks.  I've tried several times to install UAG Beta RC0 on Server 2008 R2 Enterprise Edition and every time it fails when it gets to 'installing TMG'.  Here's an event log entry -&gt;<br/> <br/> Product: Microsoft Forefront Threat Management Gateway Beta EE  -- Error 1305.Error reading from file D:\ISA\FPC\program files\Microsoft ISA Server\UI_HTMLs\EE\06AlertsTab.htm.  Verify that the file exists and that you can access it.<br/> <br/> Here's the ISAWRAP_255.log -&gt;<br/> <br/> 15:34:06 INFO:    Installer activated, command-line='/v&quot; /qn REBOOT=ReallySuppress FULLPATHANSWERFILE=\&quot;C:\Users\2333\AppData\Local\Temp\TmgInstall.091112.153406.2848.ini\&quot;&quot;'<br/> 15:34:06 INFO:    Running setup wrapper in quiet mode.<br/> 15:34:06 INFO:    Expanded full extraction path of SQL Express 2008 SP1 Package is 'C:\Windows\temp\{CECBAEFD-9EB9-4C4F-8136-21C75BD74050}'.<br/> 15:34:06 INFO:    Install scenario<br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: Upgrade code is not set<br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: There is no any product code for upgrade code <br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: Upgrade code is not set<br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: There is no any product code for upgrade code <br/> 15:34:06 ERROR:    CSSEInstaller::GetInstanceId failed to open reg key 'SOFTWARE\Microsoft\Microsoft SQL Server\Instance Names\SQL'<br/> 15:34:06 INFO:    CSSEInstaller::Prepare: Failed to get the instace id of MSFW<br/> 15:34:06 ERROR:    CSSEInstaller::GetInstanceId failed to open reg key 'SOFTWARE\Microsoft\Microsoft SQL Server\Instance Names\SQL'<br/> 15:34:06 INFO:    CSSEInstaller::Prepare: Failed to get the instace id of ISARS<br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: Upgrade code is not set<br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: There is no any product code for upgrade code <br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: Upgrade code is not set<br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: There is no any product code for upgrade code <br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: Upgrade code is not set<br/> 15:34:06 INFO:    CMsiAttendantInstaller::Prepare: There is no any product code for upgrade code <br/> 15:34:06 INFO:    Installing ISA (Core components)...<br/> 15:34:06 INFO:    Service W3SVC is running.<br/> 15:34:06 INFO:    Service iisadmin is stopped.<br/> 15:34:06 INFO:    CFirewallInstaller: Activating installation, command line args = '-I &quot;D:\ISA\FPC\MS_FPC_Server.msi &quot; /qn REBOOT=ReallySuppress FULLPATHANSWERFILE=&quot;C:\Users\2333\AppData\Local\Temp\TmgInstall.091112.153406.2848.ini&quot; WRAPPER=1 ARPSYSTEMCOMPONENT=1 REBOOT=ReallySuppress'<br/> 15:34:49 ERROR:    Setup failed. Error returned: 0x643<br/> 15:34:49 ERROR:    CBasicInstaller: Install failed, hr=0x80070643<br/> 15:34:49 ERROR:    Installation failed. hr = 0x80070643<br/> 15:34:49 ERROR:    Installation failed, hr=0x80070643<br/> 15:34:49 INFO:    Service W3SVC is running.<br/> 15:34:49 INFO:    Service iisadmin is stopped.<br/> 15:34:49 ERROR:    InstallProducts: Install ISA (Core components) failed, hr=0x80070643<br/> 15:34:49 ERROR:    Wrapper: Install failed, hr = 0x80070643<br/> 15:34:49 ERROR:    Wrapper: DoSetup failed, hr = 0x80070643<br/> 15:34:49 ERROR:    Wrapper: DoSetup failed, hr = 80070643<br/> 15:34:49 ERROR:    Setup of ISA failed. Return value: SETUP_ERROR_ISA<br/>Thu, 12 Nov 2009 20:48:46 Z2009-11-16T17:50:23Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/a4946481-bc4c-4b7f-bc68-53b813a5004ahttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/a4946481-bc4c-4b7f-bc68-53b813a5004aDarrenBonehillhttp://social.technet.microsoft.com/Profile/en-US/?user=DarrenBonehillNetwork Connector Server settings<p>When setting up the newtork connector server their is and adnvanced tab that has a section for server resources. Could anybody explain what those fields are for and what they do. HAs anybody changed these settings to get NC working better ?</p>Mon, 09 Nov 2009 16:30:14 Z2009-11-12T13:59:18Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5b3d2a5a-dbf6-43ec-881f-d7ab6f36241chttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5b3d2a5a-dbf6-43ec-881f-d7ab6f36241cJason Revillhttp://social.technet.microsoft.com/Profile/en-US/?user=Jason%20RevillUAG RC0 Activation removes TMG policies randomly/ Certified Endpoints/ AES 256Hello all,<br/><br/>I just wanted to let someone know that on my test installation of UAG RC0 it seems that when I am published RDS conenction's and activate them the UAG Management app deletes the majority of the TMG firewall policies required to access the Portal. I'm working around this by simply backing up the TMG whenever a successful activation occurs. I wasn't sure how to report back issues with the RC so I'm trying my best and publishing it here...<br/><br/>Has anyone managed to get Certified Endpoints working with the RC0, I have a client certificate installed as standard on my workstation's and my UAG Certifiacte is a trusted internal Server certificate, I have installed all the Whale Endpoint software and try to coax my connection's into being Certified Endpoints only with the Access Policies but still no joy, what am I missing?<br/><br/>Also, does anyone know how to force AES 256 encryption on Server 2008 R2, I've seen the how to on  Server 2003, but 08 R2 does not have the reg key for AES??<br/><br/>Any help would be greatly appreciated :)Thu, 12 Nov 2009 09:50:19 Z2009-11-12T09:50:21Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/34c82d47-d287-4636-adf1-b208867a17e8http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/34c82d47-d287-4636-adf1-b208867a17e8Prashant Bhandarihttp://social.technet.microsoft.com/Profile/en-US/?user=Prashant%20BhandariIAG translations/Custom changes<p class=MsoNormal><span style="font-size:11pt;color:#1f497d;font-family:'Calibri','sans-serif'"><span style="color:#000000">Hi All,<br/><br/>This forum has been excellent to know things about IAG and I cant stop thanking enough Mark and Ben on their consistancy!!!<br/><br/>can some please explain what is SRA.I tried to search it on google and technet.I could not get any information on it, not even in the user guide as well but the closest I could get is this:<br/><br/>1. Sometimes, applications may contain client-side code (like JavaScript or Vbscript) that cannot be automatically rewritten; this is the case <br/>especially with very complex web applications that rely heavily on client-side logic to generate URLs. In these cases, specific sections of the <br/>script or HTML code may need to be rewritten using either an application wrapper or SRA template.<br/><br/>I come across isssues where in Javascript gives errors and wouldnt work so I believe in those cases I would have to write an SRA.Can anyone please throw <br/>some light on how we write and what exactly is an SRA?<br/><br/>2.  Also, why do we use JavaScript parser and how is it different than the SRA or application wrapper.<br/><br/>Java script parser is used in responses only. It is defined in the AAP  configuration file in the element &lt;PARSER_EXCEPTION&gt;<br/>I tried to look for parser exception but was not able to comprehend it...can anyone help explaining it.<br/>PARSER_EXCEPTION:-  Defines all the JavaScript commands that are parsed; the links that are found within those commands are manipulated, . By default, <br/>the parser is configured to parse all standard commands that contain links. You can edit the file to add other, non-standard commands, which might <br/>contain links in your application.<br/></span><span style="color:#000000"><br/>3. The information sent from IAG to the application server is in which of these (or all of them could apply) ?<br/>SSL 2.0<br/>SSL3.0<br/>TLS1.0<br/></span><br/>4. How does IAG handle Flash rewrites (SWF) or sites which have Flash based images?<br/></span></p> <p>I read it somwhere that  IAG cannot rewrtie the absolute URL's within the swf / flash content type because its a compiled bytecode. IAG doesnt know how to handle these SWF URL's and therefore you cant tell the IAG engine to HAT the URL's if you are publishing a flash based application via IAG.<br/>Can “HAT via Proxy” resolve it?<br/><br/><span style="color:#000000">Thanks and regards<br/>Prashant Bhandari<br/></span>nAppiance Networks- Application protection and acceleration<br/><a href="http://www.nappliance.com">www.nappliance.com</a></p>Tue, 10 Nov 2009 20:42:18 Z2009-11-12T20:26:11Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5329854c-ec2a-47e2-993e-3153df082125http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/5329854c-ec2a-47e2-993e-3153df082125mattiboombalattihttp://social.technet.microsoft.com/Profile/en-US/?user=mattiboombalattix64 Client Support<p>Are Windows Vista x64 and Window 7 x64 supported in UAG 2010?  I have published RDP in UAG 2010 Beta 2 but my x64 clients cannot use the RDP links.  Is there a way to make those work?  They just come up with an error that its's not supported.  It would appear that x64 clients are at a disadvantage.<br/><br/>Given that IAG and UAG are enterprise-level products, we should be able to support x64 clients fully!!!  If you go to a computer store now, almost all of the laptops they are selling are x64.  It's hard to even find an x86 client anymore.<br/><br/>Also, what is the plan for x64 support with IAG 2007 SP2?</p>Tue, 10 Nov 2009 17:31:40 Z2009-11-11T18:41:09Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/be4942b1-d382-4702-85e2-2e5a264d9140http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/be4942b1-d382-4702-85e2-2e5a264d9140bordermanhttp://social.technet.microsoft.com/Profile/en-US/?user=bordermanCorporate Status IndicatorHi,<br/><br/>We cannot get the Network Tray icon display &quot;Internet and Corporate&quot; when conncted with UAG Directaccess.<br/><br/>The Network Connectivity Status Indicatorshow policys are configured. What can be the problem?<br/><br/>ThanksTue, 10 Nov 2009 20:05:05 Z2009-11-11T18:39:48Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/e171435e-dace-46b6-9b3a-803395128903http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/e171435e-dace-46b6-9b3a-803395128903Mohammad Nasirihttp://social.technet.microsoft.com/Profile/en-US/?user=Mohammad%20NasiriCan ISA Server 2006 authenticate domain user accounts when working as a workgroup computer ?Hello Friends :<br/><br/>I have a standalone ISA Server 2006  installed, and i also have an active directory domain, can i sa server authenticate users from active directory when it is not joined to it ?<br/><br/>thank you. <hr class=sig> Network is my LOVESun, 08 Nov 2009 12:33:08 Z2009-11-11T08:32:37Zhttp://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/0a1402d6-26a3-4ace-925c-d6adffabfec1http://social.technet.microsoft.com/Forums/en-US/forefrontedgeiag/thread/0a1402d6-26a3-4ace-925c-d6adffabfec1DarrenBonehillhttp://social.technet.microsoft.com/Profile/en-US/?user=DarrenBonehillNetwork Connector Dropping session after 1 - 3 mins<p>A client is currently running IAG SP2 Update1 and we seem to be having problems with the Network Connector dropping the session after 1 - 3 mins.  The client is connecting using a T-Mobile 3G dongle. Connectivity through Wireless or LAN connection seems to be fine.<br/><br/>Has anybody got any ideas of what may be causing this problem. The dongle shows good reception and somestimes it shows this behaviour and then other times it we work okay.<br/><br/>Thanks in advance<br/><br/>Darren</p>Mon, 09 Nov 2009 15:37:57 Z2009-11-10T16:44:20Z