Forefront Threat Management Gateway ForumDiscussions and questions on Forefront Threat Management Gateway, the next generation of ISA Server.© 2009 Microsoft Corporation. All rights reserved.Wed, 02 Dec 2009 05:36:46 Zdbc55340-0c95-4c6f-80d8-4e126178d3c8http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/d246e7de-07ed-49ef-970c-d9cbd03386dahttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/d246e7de-07ed-49ef-970c-d9cbd03386daDan112233http://social.technet.microsoft.com/Profile/en-US/?user=Dan112233Traffic Being BlockedI'm having some trouble getting Forefront TMG to work properly.  I have created a rule to allow all traffic from the FTMG server to any network, and that rule works just fine.  However traffic returned from such requests is denied.  <br/><br/>For example, if I try to browse a website, I see that the request is sent out and allowed, but that the response back from the web server is being denied.  It's like it's not tracking stateful information.  <br/><br/>This is preventing the server from funcitoning at all, I can't even get my server to activate.  I'm running Windos 2008 Server Standard, 32 bit.  Any help would be gratly appreciated.Tue, 01 Dec 2009 17:28:17 Z2009-12-02T05:36:46Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1f8dc1cb-268a-4e04-897d-9a5d57274acbhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1f8dc1cb-268a-4e04-897d-9a5d57274acbShahinhttp://social.technet.microsoft.com/Profile/en-US/?user=Shahinpublishing POP3 FailedHi, <br/><br/>we did setup an test enviorment with Exchange Exchange 2007 Hub Transport and Mailbox role on one server, Exchange Edge and ISA and FEP 2007 on othere server, now I would like to publish the standard POP3 (not secure), so I did first subscrrib the Edge with Hub (then went ok),then i used wizard for publish an mail server, then choose the standard POP3. after I did connect an PC to the same network rang of external NIC of ISA, then on this PC I did setup the outlook to point to the external IP of NIC for the POP3 Server,I also create an test user account and mailbox, but the problem is here, when I say to check configuration it find the POP server and I get an logging prompt I try the test username and password but I get the propmt back.I also did check the logs of ISa and it says connection on port 110 initiated <br/>the outlook version is 2003 <br/>I want to also add that when I telnet the external NIC of ISA on port 110 I get: <br/>+OK Microsoft Exchange Server 2007 POP3 service ready <br/><br/><br/><br/>I also in the property of the role did check the option request coming from ISA server <br/><br/>this is my configuration: <br/><br/>ISA has 2 nics, <br/><br/>intern: 10.0.0.1 <br/>Extern: 62.221.189.145 <br/><br/>Exchange: 10.0.0.11 <br/><br/>External Client: 62.221.189.150 <br/><br/>Any idea why is this heppening? <span class=info><br/></span>Tue, 01 Dec 2009 15:09:23 Z2009-12-02T05:33:19Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/41044415-e8c1-4818-9f8e-a19d645ae273http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/41044415-e8c1-4818-9f8e-a19d645ae273bassjacehttp://social.technet.microsoft.com/Profile/en-US/?user=bassjaceISA 06 & Windows 7 problemHi,<br/>I have a Server 2008 R2 domain that has a ISA 06 at the gateway with Firewall and Web Proxy enabled. I am using DNS and DHCP to hand out WPAD and auto config script. Most clients have the firewall client installed. I require authentication for internet access for all users therfore I do not hand out the gateway IP. there is no SecureNAT.<br/>I have a mix of XP and Vista machines that have Outlook installed and therfore I have the firewall application setting for Outlook set to Disable 0. This enables outlook to poll for mail on the external mail servers without a gateway assignment, the firewall client does not ignore the mail request.<br/>Since installing windows 7 machines and giving them the same setup as all the XP and Vista machines with Firewall Client I am unable to poll for mail with them without handing them a gateway. The windows 7 machines when set to autoconfig script assignment without the gateway can internet browse OK but no polling for mail. When I log the access on ISA there is nothing, no traffic when you send receive. The outlook message is &quot; server cannot be contacted or is down&quot; The outlook client does not know where to go to poll for mail. Again if you iniate a browser it can get onto the Net, but no mail. ISA logs show this traffic OK.<br/>Give the client a gateway and instantly the Windows 7 Outlook client receives mail.<br/>I don't understand why this is isolated to just the Windows 7 machines. For the time being I have to set either static IP's on windows 7 machines with a gateway who require outlook mail access or do a reservation with scope options again with a gateway.<br/>All the Xp and vista machines work as they should, no gateway with firewall client and autoconfig + WPAD. Firewall client application settings for Outlook set to Disable 0. Message delivery is successful.<br/>Same setup on windows 7 and it can't find the server as it has no gateway.<br/>What am I doing wrong?<br/>Can anybody assist?<br/>Much appreciated...........Wed, 02 Dec 2009 00:45:21 Z2009-12-02T00:45:22Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/15d9b17a-c9c4-47b7-aeb0-6630508e6b3fhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/15d9b17a-c9c4-47b7-aeb0-6630508e6b3fShahinhttp://social.technet.microsoft.com/Profile/en-US/?user=Shahinpublish smtpI did install exchange 2010 (hub and mailbox roles) on a server, then install the Exchange 2010 edge role and FPE 2010 on a diffirent server and did install the TMG 2010 on the same server as edge and FPE.<br/>now my question is do we have to still publish the smtp through TMG 2010? or this not neccecry? if we have to publish SMTP, does anyone has an toturial on how to do this?<br/><br/>Thanks,<br/><br/>Shahin<br/><hr class="sig">ShahinTue, 01 Dec 2009 11:38:01 Z2009-12-01T17:19:14Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/ba49fb03-9293-4dd1-9f75-121f08bef638http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/ba49fb03-9293-4dd1-9f75-121f08bef638Anton Spitsynhttp://social.technet.microsoft.com/Profile/en-US/?user=Anton%20SpitsynTraffic shapingWe look for software solution for traffic shaping (<a href="http://en.wikipedia.org/wiki/Traffic_shaping">http://en.wikipedia.org/wiki/Traffic_shaping</a>) with Forefront TMG.<br/>Do you have any guess how to implement this?<br/>If Forefront TMG have no built-in features due to traffic shaping, maybe  third party and/or partner solutions can help?<br/>I believe that traffic shaping and traffic policing for TMG/ISA exist.Mon, 30 Nov 2009 09:23:16 Z2009-12-01T05:39:56Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/55cdbe3a-9575-4dc8-b86c-e02bb7545051http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/55cdbe3a-9575-4dc8-b86c-e02bb7545051Kevin Oliverhttp://social.technet.microsoft.com/Profile/en-US/?user=Kevin%20OliverPublishing CRL through TMGTrying to create a website publishing rule for my internal CRL list. <br/><br/>internal site is <a href="http://DC01/certenroll/">http://DC01/certenroll/</a><br/>external is CRL.&lt;domainname&gt;.com<br/>public IP for TMG is set to CRL.&lt;domainname&gt;.com<br/>rule and listener is create for crl.&lt;domainname&gt;.com<br/>but the rule keeps getting skipped and gets blocked by the default rule. testing the rule succeds. not sure what else i am missingWed, 22 Jul 2009 20:26:03 Z2009-11-29T08:51:19Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/e64088cc-a54a-4da7-b6ed-f7476a0f6f03http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/e64088cc-a54a-4da7-b6ed-f7476a0f6f03LK123http://social.technet.microsoft.com/Profile/en-US/?user=LK123Preferred editions of Windows server 2008 for TMG 2010 deployment ?Hi,<br/><br/>    It seems that Forefront TMG 2010 (RTM version) only supports &quot;Windows Server 2008 SP2&quot; or &quot;Windows Server 2008 R2&quot;<br/><br/>What about TMG 2010 support for other 64-bit editions of Windows server 2008. ?  <br/><br/>Is it possible to deploy TMG 2010 on other flavors of Windows 2008 like : Windows Server 2008 Datacenter , Windows Server 2008 R2 Datacenter,  Windows Server 2008 Standard and Windows Server 2008 R2 Standard?<br/><br/>Also, Can anyone please tell us, the preferred editions of Windows server 2008 widely used for TMG 2010 deployment in an organization?<br/><br/>Thanks,<br/>LK<br/><br/><br/><br/>Thu, 26 Nov 2009 16:13:43 Z2009-11-26T20:37:15Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/7ff0a106-a1f9-40ec-a872-12606060e680http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/7ff0a106-a1f9-40ec-a872-12606060e680rudi01http://social.technet.microsoft.com/Profile/en-US/?user=rudi01Howto protect TMG client for change configurationHow I protect TMG client for change configuration ?<br/><br/>User without administrative rights is possible disable to TMG FWC - how block it ?<br/>Via GPO ? - where is ADM/ADMX files ?<br/><br/>Thanks,<br/>L.Thu, 26 Nov 2009 10:39:05 Z2009-11-26T20:34:19Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/74b386fc-fdb8-445f-bf27-e1d65cf2937ehttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/74b386fc-fdb8-445f-bf27-e1d65cf2937eShahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinWeb protectionHi,<br/><br/>After installing the TMG RTM when configuring Define Deployment Option, it ask if we want to enable NIS and web protection, on NIS I though just live it enable but on web protection it says: start using the evaluation licence or use a licence (this is not possible becuse the licence is not available yet) or disabling it, I would like to know how long is the evaluation periode? and if this option is disabled what is the consequence of that? and last question: is it possible to change this settings, once it has been configured?<br/><br/><br/>Thanks,<br/><br/>Shahin<hr class="sig">ShahinTue, 24 Nov 2009 16:23:17 Z2009-11-26T09:29:42Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/650dbfe8-8da7-4ff4-acc1-f4fe63f36d30http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/650dbfe8-8da7-4ff4-acc1-f4fe63f36d30LK123http://social.technet.microsoft.com/Profile/en-US/?user=LK123Forefront TMG 2010 support for Itanium-based Systems ?<p>Does Forefront TMG 2010 supports “Windows Server 2008 for Itanium-based Systems” ?</p> <p>We are able to run setup on Windows server 2008 (Itanium) system but not able to find any Microsoft link or references which claims support for Win 2008 (Itanium) system.</p> <p>Any idea ?</p> <p>Thanks,<br/> Lk</p>Wed, 25 Nov 2009 11:17:37 Z2009-11-25T17:12:33Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b4c3eff9-5d1a-4b96-9d8e-e11c475c9b42http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b4c3eff9-5d1a-4b96-9d8e-e11c475c9b42BadgerBlackhttp://social.technet.microsoft.com/Profile/en-US/?user=BadgerBlackFTMG 2010 TechnetGood Morning.<br/><br/>FTMG 2010 isn't currently available via Technet.<br/>Can anyone shed any light of when it may become available, if at all?<br/><br/>Regards,<br/><br/>Steve.Tue, 24 Nov 2009 11:34:07 Z2009-11-25T12:57:00Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/4d7639ed-7129-4feb-8e9b-cbe86cf02394http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/4d7639ed-7129-4feb-8e9b-cbe86cf02394karinjohttp://social.technet.microsoft.com/Profile/en-US/?user=karinjoMonitoring or real-time reporting ???Does the new ISA brings some kind of monitoring or monitoring in real time? <br/><br/><span class="medium_text"><span style="background-color:#ffffff" title="Potreban mi je firewall koji u svakom trenutku moze da pokaze meni koji racunar koristi najvise mrezu, koji protokoli se najvise koriste,">I need a firewall that at any time can show me which computer in my company use the most of the network, which protocols are most used, which user most load on the network etc...<br/><br/><span class="short_text"><span style="background-color:#ffffff" title="Da li server ima mogucnost monitoringa u realnom vremenu?">Does the TMG have the possibility of monitoring in real time?</span></span><br/></span></span>Tue, 24 Nov 2009 10:05:35 Z2009-12-01T15:01:25Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/84f629c5-c092-4868-bdde-5324fded53e3http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/84f629c5-c092-4868-bdde-5324fded53e3Maros Laurohttp://social.technet.microsoft.com/Profile/en-US/?user=Maros%20Lauro TMG Control Service - CrashI have problem with TMG Control Service. When I connect to OWA(2007) published on TMG - Control Service crash and Firewall service stops working. <br/>Sometimes it works but very occasionaly and after while Control Service crash. <br/>My Configuration: <br/>Hyper-V Server 2008 R2, 2 x Nic, 3 x Virtual Machines - W2k8 SP2, <br/>1 - Virtual Machine = TMG 2010 + Exchange EDGE 2007 SP2 <br/>2 - VM = DC, <br/>3 - VM = Exchange 2007 SP2 (Hub Transport, Client, Mailbox) <br/><br/>Event Log errors: <br/>------------------------------------------------------ <br/>Log Name:      Application <br/>Source:        Application Error <br/>Date:          17. 11. 2009 22:50:29 <br/>Event ID:      1000 <br/>Task Category: (100) <br/>Level:         Error <br/>Keywords:      Classic <br/>User:          N/A <br/>Computer:      edge.domain.sk <br/>Description: <br/>Faulting application mspadmin.exe, version 7.0.7734.100, time stamp 0x4ad4f893, faulting module ncrypt.dll, version 6.0.6002.18005, time stamp 0x49e0419b, exception code 0xc0000005, fault offset 0x000000000000310e, process id 0xb78, application start time 0x01ca67ce75f5f759. <br/>Event Xml: <br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt; <br/>&lt;System&gt; <br/>   &lt;Provider Name=&quot;Application Error&quot; /&gt; <br/>   &lt;EventID Qualifiers=&quot;0&quot;&gt;1000&lt;/EventID&gt; <br/>   &lt;Level&gt;2&lt;/Level&gt; <br/>   &lt;Task&gt;100&lt;/Task&gt; <br/>   &lt;Keywords&gt;0x80000000000000&lt;/Keywords&gt; <br/>   &lt;TimeCreated SystemTime=&quot;2009-11-17T21:50:29.000Z&quot; /&gt; <br/>   &lt;EventRecordID&gt;13150&lt;/EventRecordID&gt; <br/>   &lt;Channel&gt;Application&lt;/Channel&gt; <br/>   &lt;Computer&gt;edge.domain.sk&lt;/Computer&gt; <br/>   &lt;Security /&gt; <br/>&lt;/System&gt; <br/>&lt;EventData&gt; <br/>   &lt;Data&gt;mspadmin.exe&lt;/Data&gt; <br/>   &lt;Data&gt;7.0.7734.100&lt;/Data&gt; <br/>   &lt;Data&gt;4ad4f893&lt;/Data&gt; <br/>   &lt;Data&gt;ncrypt.dll&lt;/Data&gt; <br/>   &lt;Data&gt;6.0.6002.18005&lt;/Data&gt; <br/>   &lt;Data&gt;49e0419b&lt;/Data&gt; <br/>   &lt;Data&gt;c0000005&lt;/Data&gt; <br/>   &lt;Data&gt;000000000000310e&lt;/Data&gt; <br/>   &lt;Data&gt;b78&lt;/Data&gt; <br/>   &lt;Data&gt;01ca67ce75f5f759&lt;/Data&gt; <br/>&lt;/EventData&gt; <br/>&lt;/Event&gt; <br/>--------------------------------------------- <br/>Log Name:      Application <br/>Source:        Application Error <br/>Date:          17. 11. 2009 22:50:30 <br/>Event ID:      1000 <br/>Task Category: (100) <br/>Level:         Error <br/>Keywords:      Classic <br/>User:          N/A <br/>Computer:      edge.domain.sk <br/>Description: <br/>Faulting application mspadmin.exe, version 7.0.7734.100, time stamp 0x4ad4f893, faulting module mspadmin.exe, version 7.0.7734.100, time stamp 0x4ad4f893, exception code 0xc0000005, fault offset 0x00000000000f0ab0, process id 0xb78, application start time 0x01ca67ce75f5f759. <br/>Event Xml: <br/>&lt;Event xmlns=&quot;<a href="http://schemas.microsoft.com/win/2004/08/events/event">http://schemas.microsoft.com/win/2004/08/events/event</a>&quot;&gt; <br/>&lt;System&gt; <br/>   &lt;Provider Name=&quot;Application Error&quot; /&gt; <br/>   &lt;EventID Qualifiers=&quot;0&quot;&gt;1000&lt;/EventID&gt; <br/>   &lt;Level&gt;2&lt;/Level&gt; <br/>   &lt;Task&gt;100&lt;/Task&gt; <br/>   &lt;Keywords&gt;0x80000000000000&lt;/Keywords&gt; <br/>   &lt;TimeCreated SystemTime=&quot;2009-11-17T21:50:30.000Z&quot; /&gt; <br/>   &lt;EventRecordID&gt;13151&lt;/EventRecordID&gt; <br/>   &lt;Channel&gt;Application&lt;/Channel&gt; <br/>   &lt;Computer&gt;edge.domain.sk&lt;/Computer&gt; <br/>   &lt;Security /&gt; <br/>&lt;/System&gt; <br/>&lt;EventData&gt; <br/>   &lt;Data&gt;mspadmin.exe&lt;/Data&gt; <br/>   &lt;Data&gt;7.0.7734.100&lt;/Data&gt; <br/>   &lt;Data&gt;4ad4f893&lt;/Data&gt; <br/>   &lt;Data&gt;mspadmin.exe&lt;/Data&gt; <br/>   &lt;Data&gt;7.0.7734.100&lt;/Data&gt; <br/>   &lt;Data&gt;4ad4f893&lt;/Data&gt; <br/>   &lt;Data&gt;c0000005&lt;/Data&gt; <br/>   &lt;Data&gt;00000000000f0ab0&lt;/Data&gt; <br/>   &lt;Data&gt;b78&lt;/Data&gt; <br/>   &lt;Data&gt;01ca67ce75f5f759&lt;/Data&gt; <br/>&lt;/EventData&gt; <br/>&lt;/Event&gt; Sat, 21 Nov 2009 00:26:00 Z2009-11-25T01:06:05Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/761d33d7-7b91-4ad4-8766-7da291794f75http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/761d33d7-7b91-4ad4-8766-7da291794f75BadgerBlackhttp://social.technet.microsoft.com/Profile/en-US/?user=BadgerBlackFTMG 2010 Trial Expiration Date.Good Morning All.<br/><br/>Does anyone know when a trial installation  of TMG 2010 will expire?<br/><br/>Regards,<br/><br/>Steve.Tue, 24 Nov 2009 11:31:14 Z2009-11-25T12:55:57Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/ef151003-ebdb-41ff-9633-0c2ca6c74e29http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/ef151003-ebdb-41ff-9633-0c2ca6c74e29Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinTerminal ServicesHi,<br/><br/>Could someone direct me to some artical on how to configuer the TMG or ISA 2006 for Terminal services, our clients accessing some of our servers to use certine applications, now we want to implament ISA 2006 or TMG in our network, so clients most first make VPN connection and then start an RDP session to there servers<br/>my question is,<br/>what is the next step here? should we create access rules on ISA to access T.S servers? or that is not nececery?<br/><br/>Thanks,<br/><br/>Shahin<hr class="sig">ShahinTue, 24 Nov 2009 15:30:17 Z2009-11-25T08:56:10Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/a5fd8b6e-e4ea-4f75-8eab-b71bac7168dehttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/a5fd8b6e-e4ea-4f75-8eab-b71bac7168deShahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinSQL Reporting failed Hi,<br/><br/>I did download the TMG (the RTM version), but I have to say that before that we had on the dame server the TMG Candidate release and I did first remove this version to install the new version, now when I install the software at the end of installation syas:<br/><br/>Microsoft SQL server Express reporting  couldnot be installed.<br/><br/>after clicking ok it says for more info go to C:\program files\SQL server\100\Bootstrp setp\logs for more info, but I could not find any logs here.<br/><br/>Any idea why is this heppening?<hr class="sig">ShahinTue, 24 Nov 2009 15:40:04 Z2009-11-25T00:36:41Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/819bd3f1-e068-4311-ae26-e4a8a0928280http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/819bd3f1-e068-4311-ae26-e4a8a0928280Summitprephttp://social.technet.microsoft.com/Profile/en-US/?user=SummitprepWeb filtering without proxy?Here is my setup, I run the network for a high school and I am testing out tmg, However It seems like in order to filter sites, you have to setup a proxy. For the schools computers that are on the domain, thats not a problem. However we allow students to join the wireless network and it seems like they could get around it by disabling the proxy. I dont want to have to make a rule that denys them interent if they are not joined to the proxy because some computers disable the obtaining proxy information from the DHCP.<br/> <br/> So what are my options here? I would also like to add that these are high school students, they are not the most computer savy in the world, so we dont want to do anything to their computers for this to work.<br/> <br/> <br/> Also when is TMG going to be posted on technet?Wed, 18 Nov 2009 23:49:32 Z2009-12-01T15:35:20Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/aa354159-b5a0-4bf2-bb78-82d76e707a26http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/aa354159-b5a0-4bf2-bb78-82d76e707a26jwbrownhttp://social.technet.microsoft.com/Profile/en-US/?user=jwbrownMoving from TMG RC to RTMWhen the RC was released, I installed it on 2008 R2 server in order to continue testing before it was RTM. According to:<br/><br/><a href="http://blogs.technet.com/isablog/archive/2009/10/11/forefront-threat-management-gateway-2010-release-candidate-now-available.aspx">http://blogs.technet.com/isablog/archive/2009/10/11/forefront-threat-management-gateway-2010-release-candidate-now-available.aspx</a><br/><br/>we should be able to move to RTM no problem from RC. Now that RC has been released, I would like to do this but have not seen any documentation as to how to do. I am a volume license customer and have the license key available. Do I enter this somewhere in the RC to license it or do an &quot;in place upgrade&quot; with the RTM version? Thanks.<br/><br/>JeffTue, 24 Nov 2009 15:57:57 Z2009-11-24T23:57:58Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/37619d97-9fa4-44c1-8ec6-a06c82b446e4http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/37619d97-9fa4-44c1-8ec6-a06c82b446e4Kevin Oliverhttp://social.technet.microsoft.com/Profile/en-US/?user=Kevin%20OliverHTTP listener does don't redirect to internal siteHi all, <br/>Have a little trouble with a HTTP listener i setup, setup a firewall rule for  a site, created a listener that checks both HTTP and HTTPS, added the cert and tested the rule, was succesful in reaching the webpage from the TMG box. <br/><br/>the problem part now, when i try to connect externally from the http:// address, the connect is blocked by the default rule. but if i use the Https:// the listener succeds in redirecting me to the site. Not sure what i am missing on this one. <br/><br/>Error in the log state the connection was blocked by the default rule. <br/>Thu, 05 Nov 2009 19:39:06 Z2009-11-25T00:40:28Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/153b58bc-6f0d-492f-b602-48bebcf74305http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/153b58bc-6f0d-492f-b602-48bebcf74305CSalustianohttp://social.technet.microsoft.com/Profile/en-US/?user=CSalustianoStatus: 0x80072741 WSAEADDRNOTAVAIL What I can do ?When clint try to get e-mail  connections failed with this error message:<br/>Failed Connection Attempt R0002SRV 10/11/2009 13:00:04 <br/>Log type: Firewall service <br/>Status: 0x80072741 WSAEADDRNOTAVAIL <br/>Rule: Allow Web Access for All Users <br/>Source: Internal (192.168.251.116:51130) <br/>Destination: External (66.228.121.124:110) <br/>Protocol: POP3 <br/><br/>I try the sugested on<br/> <a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;927695">http://support.microsoft.com/default.aspx?scid=kb;EN-US;927695</a> <br/><br/>AND disable &quot;Receive Side Scaling&quot; hardware options on all networks interface on my Dell server (one Broadcon and one Intel)<br/><br/>Can someone help me?<br/>Tue, 10 Nov 2009 16:00:24 Z2009-11-24T13:44:21Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b1c319db-9f1f-41ff-ab52-d829f044e72bhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b1c319db-9f1f-41ff-ab52-d829f044e72bNathalie Leshttp://social.technet.microsoft.com/Profile/en-US/?user=Nathalie%20LesStandard Vs Enterprise !<p>Hello.<br/><br/>Previously with TMG beta one and two, there was no standard and enterprise versions of TMG, why with TMG beta three this change ?</p> <p>For example, in Tarek's article (<a href="http://www.elmajdal.net/ISAServer/Installing_Forefront_Threat_Management_Gateway_Beta_2.aspx">http://www.elmajdal.net/ISAServer/Installing_Forefront_Threat_Management_Gateway_Beta_2.aspx</a>)  &quot;<em><span class=style164><span style="color:#ff0000">As you may have noticed, the concept of <strong>Standard Edition</strong> or <strong>Enterprise Edition</strong> is no more available with Forefront TMG. </span></span>There are new terms that we will have to get used to them , such as Standalone Server, Array Manager, Standalone Array, Enterprise Management Server (EMS). You might find it misleading at the current moment. Don't feel that, later on we will get used to these terms, and they will be covered in future articles. To give you a brief illustration, at the moment I'll be installing a <strong>Standalone</strong> Forefront TMG server.</em> &quot;<br/><br/>and i've seen this also on different forums and blogs as well, but now I feel myself lost why this was not illustrated before ! that there will be a standard and enterprise editions again !</p> <p>and where can we find any difference between the two ?</p>Sat, 27 Jun 2009 07:38:52 Z2009-11-24T13:32:10Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/ef37e149-27ce-4da9-8739-cc58fdba46dchttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/ef37e149-27ce-4da9-8739-cc58fdba46dcNWoffordhttp://social.technet.microsoft.com/Profile/en-US/?user=NWoffordRemote Desktop Connection to Forefront TMG ServerI am trying to remotely manage the Forefront TMG server but I can't seem to get it to work. I have added my desktop's IP address to the Enterprise Remote Management Computers and have made sure the system policy is set to allow connections from the group. When I try to connect via RDP on my desktop, it just times out trying to connect. <br/><br/>The logs show the connection initiating but then it closes without connection. The log shows, &quot;A connection closed becasue no SYN/ACK reply was received from the server.&quot;Mon, 16 Nov 2009 17:31:28 Z2009-11-25T00:52:36Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/0dc99eda-7346-4d9f-b8cd-bfacbb26bc92http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/0dc99eda-7346-4d9f-b8cd-bfacbb26bc92Boudewijn Plomphttp://social.technet.microsoft.com/Profile/en-US/?user=Boudewijn%20PlompYou must restart this computer before installing Forefront TMG (final trial release)Hi,<br/><br/>I am very happy that Microsoft has released the final version of TMG Server 2010. At this moment and as far as I know you can only download the trial. I have downloaded the trial version. But I cannot install it because I get a warning message during the Installation Wizard and setup cannot continue.<br/><br/>1. Deployed a new and clean Virtual Machine with Windows Server 2008 R2 (x64); succesfully<br/>2. Run Windows Update; succesfully<br/>3. Run Preperation Tool; succesfully<br/>4. Run Installation Wizard; warning meesage<br/><br/>Then, the Installation Wizard says &quot;<strong>A computer restart is required. You must restart this computer before installing Forefront TMG</strong>&quot;. But... when you restart the server, it keeps coming with this error message. You can restart as often as you want, same result. <br/><br/>At isaserver.org I saw the same issue. <a href="http://forums.isaserver.org/m_2002095201/mpage_1/key_/tm.htm#2002095201">http://forums.isaserver.org/m_2002095201/mpage_1/key_/tm.htm#2002095201</a><br/><br/>I know there is a status in the registery somewhere and you can clean it. But I don't know where anymore and if this will result in unwanted behaviors. Any suggestions?<br/><br/>Boudewijn<br/><br/><br/>Mon, 23 Nov 2009 14:55:22 Z2009-11-23T14:55:23Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/0e6446e0-f58e-423d-8492-edcfd8d599eehttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/0e6446e0-f58e-423d-8492-edcfd8d599eeMike.N1http://social.technet.microsoft.com/Profile/en-US/?user=Mike.N1ForeFront TMG as Hyper-V guest<p>I'm using TMG in a Win 2008 Hyper-V virtual environment using a physical server (Athlon 64 x2- 5600+/8GB Ram/Dual NIC) and setup a lab environment with the following configuration:</p> <p>DNS server(also Domain PDC server): Win08 STD, One Virtual NIC (IP:192.168.3.1/255.255.255.0 GW:192.168.3.254)<br>TMG Server: Win 2008 STD (stand alone domain member), Dual virual NICs: Public nic (IP:192.168.2.254/255.255.255.0 GW:192.168.1.254 NO DNS IP) and Local NIC(IP:192.168.3.254/255.255.255.0 DNS:192.168.3.1 No GateWay IP)</p> <p>As it's suggested by Microsoft, the TMG server is refering to internal DNS server on Local NIC and has just one Gateway on Public NIC. <br>What I'm experiencing is that I can not lookup DNS records on both (virtual) servers and because of that I don't have internet access on both TMG and DNS server. </p> <p>I noticed when I'm doing a nslookup on DNS server (or TMG) the TMG logs show all the requests from DNS server denied by Default rule (that denies all traffics) Then I created an Allow policy to allow DNS requests (port 53) from Internal network to External networks. Now I see that the nslookup initiated requests comming from DNS server are getting allowed to the external DNS server (192.168.1.254) by the new policy but the closing response is not getting back from the external DNS and because of that the DNS lookup fails. </p> <p>I thought TMG should allow DNS lookups by default using system policies (like what ISA 2006 was doing) and if not, then why it's still not working after creation of the allow DNS policy?</p> <p>I thought maybe it's because I'm using TMG as virtual and did a reseach and followed on the direction to set EnableTCPA and EnableRSS to (DWord) 0 and disabled task offload for both NICs on TMG virtual but still no luck. I wonder if anybody have the solution and can help with this.</p><br><br>Wed, 06 Aug 2008 19:00:56 Z2009-11-20T11:53:59Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1feb0722-c824-4ad5-a4f4-c4141594e674http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1feb0722-c824-4ad5-a4f4-c4141594e674Flo.W.http://social.technet.microsoft.com/Profile/en-US/?user=Flo.W.PPTP VPN / DNS issueHi guys,<br/><br/>i recently set up a testbox with ForeFront TMG with VPN access using PPTP, DHCP address assignment from the internal network DHCP. The configuration was straight forward and most settings were kept by default.<br/>I firewall rule is in place which allows VPN clients complete access (all protocolls) into the internal network.<br/><br/>The clients can connect via VPN will get a IP from the DHCP but do not register in DNS.<br/>I already put in manually the option (on the client) to register in DNS but did not help.<br/><br/>I can ping and resolve FQDN of all clients and servers in the internal network but not vise versa.<br/>The VPN clients cant ping or resolve there names neither.<br/><br/>// I think the TMG Server accquires the IP addresses from the DHCP so the VPN clients wont get any further configuration and do not register in DNS either.<br/><br/>Is that by design or can I get the VPN clients resolving each other and the internal servers to resolve external clients?<br/><br/>Another questions would be if the VPN clients can resolve additional configuration from the DHCP like WPAD.dat configuration etc.?<br/><br/><br/>Thank you for help in advace!<br/><br/>Cheers,<br/><br/>FlorianTue, 17 Nov 2009 23:25:13 Z2009-11-19T12:06:23Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/930c1d58-d423-4e05-8f24-ae9263deb834http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/930c1d58-d423-4e05-8f24-ae9263deb834greythttp://social.technet.microsoft.com/Profile/en-US/?user=greytReporting Failure with RCI was running TMG Beta 3 on 2008 server without any problem. I upgraded to TMG RC and reporting now generates reports without any data. <br/><br/>I uninstalled &amp; reinstalled and this made no difference. In the end I tried :- <br/><br/>Decomission old server and remove from domain <br/>Build new 2008 R2 server with the same name and join to the domain <br/>Install TMG and import old configuration <br/><br/>This still hasnt made any difference. I am getting the error :- <br/><br/>The daily summary for day &quot;10/15/2009&quot; was not created. This may cause the report for this period to be inaccurate. Verify that no prior reporting configuration alerts exist, and that the reporting services on the designated Forefront TMG report server are running and accessible from all the array members. Use the source location 1001.105.7.0.7733.100 to report the failure. <br/>The failure is due to error: 0x80040e57 <br/><br/>If I go to Monitoring\Services I can see that the following are running ok :- <br/><br/>SQL Server (ISARS) <br/>SQL Server Reporting Services (ISARS) <br/>SQl Server Express <br/><br/>Any guidance greatly appreciated! <br/><br/><span class=info><br/></span>Sun, 18 Oct 2009 09:48:32 Z2009-11-19T08:40:49Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b42e108d-afbe-420d-ad0d-29115a1c6b36http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b42e108d-afbe-420d-ad0d-29115a1c6b36alexbchalmershttp://social.technet.microsoft.com/Profile/en-US/?user=alexbchalmersForce HTTPS redirect for specific published webpathIs it possible to force HTTP to HTTPS redirection for a specific published public web path?  For instance, given the following paths on <a href="http://www.contoso.com">www.contoso.com</a>:<br/><br/>/<br/>/images<br/>/pages<br/>/publicforms<br/><br/>I would want to allow public access to all paths, but ensure content to and from /publicforms is properly passed through HTTPS.<br/><br/>The web listener that I am currently using is configured for both HTTP and HTTPS connections, with no redirection configured.  I have looked at using the &quot;Notify HTTP users to use HTTPS instead&quot; option within the web publishing rule, which ensures the content is delivered through the appropriate protocol but is not as customer/user friendly as a redirect.  <br/><br/>If there are other options to support this type of deployment, I'd be happy to evaluate them as well.Tue, 29 Sep 2009 20:44:44 Z2009-11-19T06:22:33Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/2045b0e6-3af4-47b1-a5f9-da359e31c3b3http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/2045b0e6-3af4-47b1-a5f9-da359e31c3b3hedeselhttp://social.technet.microsoft.com/Profile/en-US/?user=hedeselRPC (DCOM) Behaviour on TMG RCHello,<br/><br/>I'm using TMG RC version 7.0.7733.100.I have a W2008 R2 Ent DC in Internal Network which also has Enterprise CA installed.<br/>When I try to use mmc console on TMG to request a certificate, I get an RPC error.Unchecking &quot;Enforce strict RPC compliance&quot; in System Policy's Active Directory section doesn't help either.I also tried creating a Firewall Access Rule which allows all traffic from &quot;Local host&quot; to &quot;DC&quot; and unchecking &quot;Enforce strict RPC compliance&quot; in that rule's options,but that  also didn't work.What worked in the end was,I did both at the same time;I created the rule without the RPC compliance AND disabled RPC compliance in System policy. Funny thing is, after I get the certificate, if I remove the rule I created,it still works. Btw,I not only applied each time after I made a modification but also restarted MS FF TMG Control service just to make sure.<br/><br/>Am I missing something or is this a bug?<br/>Thanks.Mon, 16 Nov 2009 20:49:17 Z2009-11-16T20:49:18Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/46c30eea-aff4-4bde-ae44-a26e241bd63ahttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/46c30eea-aff4-4bde-ae44-a26e241bd63aNewtoSCCMhttp://social.technet.microsoft.com/Profile/en-US/?user=NewtoSCCMWhat TMG version can we deploy in production environment. What TMG version can we deploy in production environment and what are the OS prerequisitesMon, 09 Nov 2009 09:09:15 Z2009-11-24T23:49:25Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/27d8c155-fbc7-4a65-89a1-9499fd6b16d6http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/27d8c155-fbc7-4a65-89a1-9499fd6b16d6yusufuhttp://social.technet.microsoft.com/Profile/en-US/?user=yusufuNLB Setting on TMGI have set up a TMG array on Hyper V virtual machine , and am trying to configure Network Load Balancing between 2 TMG machines . We have configured NLB in the Multicast mode , and are using a Single NIC for config. We are unable to get the NLB working it . Can any one help as to what should be the correct settings for our setup.Mon, 16 Nov 2009 08:47:06 Z2009-11-16T14:07:43Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/06e8c6ea-c907-433b-99d4-78c3588871a6http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/06e8c6ea-c907-433b-99d4-78c3588871a6David Jerwoodhttp://social.technet.microsoft.com/Profile/en-US/?user=David%20JerwoodTMG - PPTP VPN Connection<p>I am trying to create a PPTP VPN Client to Server Connection using TMG.<br/>I followed the setup instructions have have enabled vpn and added a firewall rule. When trying to connect from a Windows 7 client the client says connecting but after a while errors reporting a timeout.<br/>The logs within TMG monitor show a successful connection.<br/><br/>Can anybody offer me any advise, would be much appreciated.</p>Thu, 24 Sep 2009 18:55:40 Z2009-11-06T13:28:06Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/f5a71a5d-9532-4faf-84c1-2497160e0d26http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/f5a71a5d-9532-4faf-84c1-2497160e0d26nOrphfhttp://social.technet.microsoft.com/Profile/en-US/?user=nOrphfDifferencing VPN accessHi<br/><br/>I have en TMG server i front of several networks and several AD's.<br/>Can i difference what access I have when a user connects?<br/><br/>Currently I have setup vpn authentication to RADIUS (to the domaincontroller), so I can add more sources.<br/><br/>I have tried to apply one VPN access rule to only one user, but I can't seem to get i working.<br/><br/>Maybe it's something with the user I specify, even though I have tried both domain\user and <a href="mailto:user@domain">user@domain</a>, and of cause chose that its an RADIUS user.<br/><br/>/LarsThu, 05 Nov 2009 10:24:31 Z2009-11-05T10:24:32Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/3421c709-520f-40e8-9a4f-99ade21ddd26http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/3421c709-520f-40e8-9a4f-99ade21ddd26BrentSpeckhttp://social.technet.microsoft.com/Profile/en-US/?user=BrentSpeckStatus 64 Specified network name is no longer available.Seems to timeout at 3 min 20 Sec every time. While downloading a report.<br/><br/> <div class=body>Windows Server Standatd 2008 SP1<br/><br/>Forefront Threat Management Gateway  Version 6.0.6417.100 MBE<br/><br/> <table border=0 cellpadding=0> <tbody> <tr bordercolor="#2e4c75"> <th width="100%" align=left><span style="color:#ff0000">Failed Connection Attempt</span></th> <td width="100%" height=20 align=right><strong>ISA-01V 9/15/2009 11:08:00 AM</strong></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Log type: </strong>Web Proxy (Forward)</td> </tr> <tr bordercolor="#2e4c75"> <td title="64 The specified network name is no longer available. " colspan=2 width="100%" height="100%"><strong>Status: </strong><span>64 The specified network name is no longer available. </span></td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Rule: </strong>Lee - Unrestricted PCs</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Source: </strong>Internal (10.10.11.187)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Destination: </strong>External (wpmt.buildingtrustinc.com 63.171.212.39:80)</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Request: </strong>POST http://63.171.212.39/wpCompCost.aspx</td> </tr> <tr> <td colspan=2 width="100%" height="100%" align=left><strong>Filter information: </strong>Req ID: 0e140838; Compression: client=No, server=Yes, compress rate=0% decompress rate=0%</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>Protocol: </strong>http</td> </tr> <tr> <td width="100%" height="100%" align=left><strong>User: </strong>anonymous</td> </tr> </tbody> </table> </div>Tue, 03 Nov 2009 19:15:04 Z2009-11-03T19:15:06Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1340dd18-daff-4098-9800-f3826c7bc7b3http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1340dd18-daff-4098-9800-f3826c7bc7b3ManU PhiliPhttp://social.technet.microsoft.com/Profile/en-US/?user=ManU%20PhiliPWhich one is suitable for me?Hai all,<br/><br/>I am planning to have a firewall product of ISA Server family to install within our office to secure internet communication betweek office and outside. We are using Windows Server 2008 -64/32 bit server only. Which one I have to select?<br/><br/>Manu<hr class="sig">ManuPhilipTue, 03 Nov 2009 16:55:58 Z2009-11-04T03:56:04Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/6c73c2f1-dca0-4374-b517-d4f2d23f9aedhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/6c73c2f1-dca0-4374-b517-d4f2d23f9aedip-robhttp://social.technet.microsoft.com/Profile/en-US/?user=ip-robMajor issues with a remotely located TMG serverThe scenario is that I have a server that is a member of a domain.  It has TMG installed on it.  I'm not trying to set up a site-to-site VPN between the main location and this server (for testing purposes).  There is no domain controller local to the remote TMG server.  The endpoints for the site-to-site VPN are both TMG RC.<br/><br/>Here are the issues I'm seeing:<br/><br/>1. The server gets stuck in an endless logical loop.  It cannot apply the configuration with the site-to-site VPN tunnel because it can't contact the domain (event ID is 21257, the specified domain can't be contacted).  Of course it can't be contacted, the site-to-site VPN tunnel isn't up but you can't apply the configuration with the tunnel in it because it can't contact the domain.  The logic here fails my comprehension.<br/><br/>2, Once I get an L2TP site-to-site tunnel up (I created a manual tunnel to apply the configuraiton with the site-to-site tunnel!) then from the TMG gateway I can ping anything behind the other TMG gateway.  Great!  BUT anything behing the TMG gateway cannot ping anything on the remote network.  I have allowed all traffic between the two networks, see it going out on one side and nothing on the other side.<br/><br/>Is this just flakey behavior in the &quot;Release Candidate&quot;.  It seems like basic site-to-site VPN behavior is severely broken.<br/><hr class="sig">RobMon, 02 Nov 2009 20:03:29 Z2009-11-02T20:03:30Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1adaaaf0-8d02-4b58-af93-1aafa716f615http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/1adaaaf0-8d02-4b58-af93-1aafa716f615Shahinhttp://social.technet.microsoft.com/Profile/en-US/?user=ShahinFTP issueHI,<br/><br/>We having a problem with our clients PC and FTP, when clients that are behind the TMG try to open <a href="ftp://36.55.214.223">ftp://36.55.214.223</a> I get a loging box after entering the user name and passwords, we can see the content of the ftp folder, but when try to copy some file from client to FTP site I get this error:<br/><br/>200Type set to I<br/>227 entering passive mode(<span style="text-decoration:underline"><span style="color:#0066cc">36,55,214,223,12,167)<br/></span></span>550 Access Denied.<br/><br/>But when I access the same FTP site (by the same user name and password) from othere clients that are not behind the TMG server,I can connect to FTP site and copy my file there.<br/>I did create an access rule in TMG:<br/><br/>From: intertnal<br/>TO: External<br/>Protocol: FTP<br/>Users: All users<br/><br/>SO any idea why is this heppening?<br/><br/>Thanks,<br/>Shahin<br/><hr class="sig">ShahinMon, 02 Nov 2009 15:10:32 Z2009-11-03T09:24:26Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/50b93ec0-4e3e-4b69-ad7c-a19ddef0967ahttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/50b93ec0-4e3e-4b69-ad7c-a19ddef0967aDugan Zhanghttp://social.technet.microsoft.com/Profile/en-US/?user=Dugan%20ZhangRedirect http to httpsI have asp.net page with the following code:<br/><br/>&lt;%<br/>Response.Redirect(<a href="https://mysite/default.aspx">https://mysite/default.aspx</a>);<br/>%&gt;<br/><br/>By going through TMG RC, it does not redirect https, instead it just redirect http.<br/><br/>Does anyone else experience this?<br/>Fri, 30 Oct 2009 01:39:00 Z2009-10-30T01:39:00Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/df61211f-e85d-4a82-966e-16fe8b19973chttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/df61211f-e85d-4a82-966e-16fe8b19973cCharles Tavareshttp://social.technet.microsoft.com/Profile/en-US/?user=Charles%20TavaresTemplates of the errors of malware inspectionhi peoples!<br/><br/>somebody knows where is the archives of models of errors standards that are presented for the user through the malware inspection?<br/><br/>Regards!<hr class="sig">Charles S. TavaresThu, 29 Oct 2009 23:53:29 Z2009-10-29T23:53:30Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b22700a8-7741-43f5-9275-b3bac48be7c7http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/b22700a8-7741-43f5-9275-b3bac48be7c7NCokerhttp://social.technet.microsoft.com/Profile/en-US/?user=NCokerTMG Setup Fails on: (Error 37020) Setup failed while creating the services configuration. Hello <br><br>i tried to install TMG but get always the failure: (Error 37020) Setup failed while creating the services configuration.<br><br>part of log: Setup failed while creating the services configuration.<br> <p>Action 09:49:32: ConfigureFweng. Creating the services configuration...<br>09:49:33 ISA setup CA INFO   : ENTRY: ConfigureFweng, Current user is IGUS\Administrator<br>09:49:33 ISA setup CA INFO   : About to call InstallNetComponent(MS_Fweng,C:\Program Files (x86)\Microsoft ISA Server\fweng.inf)<br>09:49:33 ISA setup CA INFO   : InstallNetComponent: ComponentID MS_Fweng InfPath C:\Program Files (x86)\Microsoft ISA Server\fweng.inf<br>09:49:33 ISA setup CA INFO   : NCGetINetCfg: NetCfg 0035EF54<br>09:49:33 ISA setup CA INFO   : NCGetINetCfg: hResult 0x0, NetCfg 0035EF54<br>09:49:33 ISA setup CA INFO   : InstallNetComponent: Calling NCInstallNetComponent NetCfg 031707F8 ComponentID MS_Fweng GUID_DEVCLASS_NETSERVICE<br>09:49:33 ISA setup CA INFO   : NCInstallNetComponent: NetCfg 031707F8 ComponentId MS_Fweng ClassGuid 6FDA163C<br>09:49:36 ISA setup CA INFO   : NCInstallNetComponent: hResult 0x0 NetCfg 031707F8 ComponentId MS_Fweng ClassGuid 6FDA163C<br>09:49:36 ISA setup CA INFO   : NCReleaseINetCfg: NetCfg 031707F8<br>09:49:36 ISA setup CA INFO   : NCReleaseINetCfg: hResult 0x0 NetCfg 031707F8<br>09:49:36 ISA setup CA INFO   : InstallNetComponent Return 1<br>09:49:36 ISA setup CA INFO   : InstallNetComponent() completed<br>09:49:37 ISA setup CA INFO   : Fweng.sys was installed properly by InstallNetComponent()<br>09:49:37 ISA setup CA INFO   : EXIT: ConfigureFweng, Custom Action succeeded<br>Action 09:49:37: ConfigureServices_Rollback. <br>Action 09:49:37: ConfigureServices. Creating the services configuration...<br>09:49:37 ISA setup CA INFO   : ENTRY: ConfigureServices, Current user is IGUS\Administrator<br>09:49:37 ISA setup CA INFO   : ModifyServiceDepend(RemoteAccess, fwsrv, 1)<br>09:49:37 ISA setup CA INFO   : Found the service, add the dependency<br>09:49:38 ISA setup CA INFO   : spService-&gt;SetServiceSidType success for service fwsrv<br>09:49:38 ISA setup CA INFO   : Adding NT SERVICE\fwsrv Service-Sid permission...<br>09:49:38 ISA setup CA ERROR  : the function AddSidToNetCfgOp failed with status = 80070057 at the function AddFwsrvPermissions.<br>09:49:38 ISA setup CA ERROR  : the function AddFwsrvPermissions failed at the function ConfigureServices.<br>Setup failed while creating the services configuration. <br>MSI (s) (F8!94) [09:52:10:026]: Product: Microsoft Forefront Threat Management Gateway -- Setup failed while creating the services configuration. </p> <p>09:52:10 ISA setup CA ERROR  : Setup failed while creating the services configuration. <br>09:52:10 ISA setup CA ERROR  : (Error 37020) Setup failed while creating the services configuration. <br>09:52:10 ISA setup CA ERROR  : EXIT: ConfigureServices, Custom Action failed (0x643)<br>Action ended 09:52:10: InstallExecute. Return value 3.<br>Action 09:52:10: Rollback. Rolling back action:<br>Rollback: Creating the services configuration...<br>Rollback: ConfigureServices_Rollback<br>09:52:10 ISA setup CA INFO   : ENTRY: RestoreServicesConfiguration, Current user is IGUS\Administrator<br>09:52:10 ISA setup CA INFO   : ModifyServiceDepend(RemoteAccess, fwsrv, 0)<br>09:52:10 ISA setup CA INFO   : EXIT: RestoreServicesConfiguration, Custom Action succeeded<br>Rollback: Creating the services configuration...<br>Rollback: ConfigureFweng_Rollback<br>09:52:10 ISA setup CA INFO   : ENTRY: RemoveFweng, Current user is IGUS\Administrator<br>09:52:10 ISA setup CA INFO   : UnInstallNetComponent: ComponentID MS_Fweng<br>09:52:10 ISA setup CA INFO   : NCGetINetCfg: NetCfg 0276F974<br>09:52:10 ISA setup CA INFO   : NCGetINetCfg: hResult 0x0, NetCfg 0276F974<br>09:52:10 ISA setup CA INFO   : UnInstallNetComponent: Calling NCUninstallNetComponent NetCfg 02A856B8 ComponentID MS_Fweng<br>09:52:10 ISA setup CA INFO   : NCUninstallNetComponent: NetCfg 02A856B8 ComponentId MS_Fweng<br>09:52:11 ISA setup CA INFO   : NCUninstallNetComponent: hResult 0x0 NetCfg 02A856B8 ComponentId MS_Fweng<br>09:52:11 ISA setup CA INFO   : NCReleaseINetCfg: NetCfg 02A856B8<br>09:52:11 ISA setup CA INFO   : NCReleaseINetCfg: hResult 0x0 NetCfg 02A856B8<br>09:52:11 ISA setup CA INFO   : UnInstallNetComponent returned 1<br>09:52:11 ISA setup CA INFO   : EXIT: RemoveFweng, Custom Action succeeded<br>Rollback: PATCH_DisablePatchRemoveForSlipstream<br><br><br>Please help!</p><hr size="1" align="left" width="25%">IT-AdminFri, 11 Apr 2008 10:07:41 Z2009-10-24T12:53:49Zhttp://social.technet.microsoft.com/Forums/en/FTMGNext/thread/973bb1e6-ab77-4fc8-9e20-f03b920a04f5http://social.technet.microsoft.com/Forums/en/FTMGNext/thread/973bb1e6-ab77-4fc8-9e20-f03b920a04f5Rudáhttp://social.technet.microsoft.com/Profile/en-US/?user=Rud%u00e1Install Error<div id="result_box" dir=ltr>I'm trying to install the Windows 2008 x64 TMG in the area where I xxx.local but he's wrong: <br>Setup failed while creating the services configuration <br><br>How do I install? </div>Sat, 26 Jul 2008 03:18:53 Z2009-10-24T10:54:20Z