locked
Did July 2018 updates screw TMG on 2008 r2? RRS feed

  • Question

  • Hi guys.

    I know TMG is deprecated but we are experiencing strange behavours on TMG and I think they are related to JULY 2018 MS security/rollup updates. Anyone else experience?

    Simptoms: TMG on 2008 r2 server stops responding; you can log into console and do the reboot, after the reboot it starts working ok.

    Nothing userful on event viewer app/system... :/


    F1? Pretty please.


    bostjan - halcom d.d.

    Tuesday, July 24, 2018 7:34 PM

All replies

  • Hi Boštjan,

    We are also experiencing strange behaviour of TMG 2010 on WinSrv2008R2 (a Hyper-V VM), namely, the TMG 2010 suddenly stops communicating via the internet-facing network interface, thus resulting in complete loss of internet connectivity for the company. It's been driving us up the wall.

    Reboot of the entire virtual machine running TMG helps.

    Temporary fix:

    Created a batch that runs every minute automatically rebooting the server in case it loses connectivity as this may happen during nighttime, which is especially problematic for us. The batch script is:

    set ip="google.com"
    ping -n 2 %ip% | find "TTL"
    if errorlevel 1 shutdown -r -t 20

    As for a more permanent try for a solution, I am reverting the VM to the backed-up state from June 30 this evening to try and determine definitively whether it was the July updates that broke it...

    Main trouble is the logs don't say anything about why this might be happening, moreover there's no pattern to this, sometimes it's up for 12 hours, sometimes 36, ...

    Friday, July 27, 2018 2:52 PM
  • I'm having the same issue.  the one additional clue that i can provide is reported in the Logging search; when the outage occurs i will start to get denied traffic errors in the Log of "[System] Lockdown mode default rule".  I've done some research on reducing the amount of logging that is done and check system freespace to no avail.  i'm starting to wonder if it's a SQL Express issue since i am using SQL for logging, i'm going to test switching that to text or W3C logging.

    Update:

    server went down again after changing it to use W3C logging :(

    • Edited by Remo Imparato Tuesday, July 31, 2018 4:22 PM followup update
    Tuesday, July 31, 2018 2:31 PM
  • Just to confirm my suspicions.

    After restoring the VM from backup to a state prior to applying the July 2018 updates, the server has been running stably for 3 weeks now.

    One of the July 2018 updates destabilises it but I cannot afford to test which one.

    • Proposed as answer by Remo Imparato Wednesday, August 22, 2018 7:42 PM
    Wednesday, August 22, 2018 9:42 AM
  • I have windows auto update turned on and since the start of August I haven't had a problem.  I think the Monthly Security update in August fixed the issue.
    • Proposed as answer by GKrzak Monday, September 10, 2018 1:01 PM
    Wednesday, August 22, 2018 7:41 PM
  • Hi everybody,

    Any news about this issue ?

    I'm concerned too and since july updates my TMG 2010 server is locked after 24 to 48 Hrs after starting.

    Thanks


    Pascal.

    Tuesday, August 28, 2018 10:02 AM
  • I haven't had an issue for all of August.  I think the August updates resolved the issue.
    • Proposed as answer by GKrzak Monday, September 10, 2018 1:01 PM
    Tuesday, August 28, 2018 1:23 PM
  • alas... not in my case...

    can you tell me what updates has been installed in august ?

    Thanks


    Pascal.

    Tuesday, August 28, 2018 3:28 PM
  • Any updates on this issue? I think we are experiencing them as well.
    Thursday, September 6, 2018 6:48 PM
  • The highlighted (top) one in the image is what I think fixed it (KB4343900), but I haven't done any research to prove it.

    the image contains all the updates applied to the server between the time of breaking and then working again.


    • Proposed as answer by GKrzak Monday, September 10, 2018 1:00 PM
    Thursday, September 6, 2018 6:58 PM
  • Thanks for the info. I'll do some research on that update on my end. 
    Thursday, September 6, 2018 7:21 PM
  • Hello,

    KB4343900 wasn't installed on my server.

    I just installed it and now, wait and see...


    Pascal.

    Friday, September 7, 2018 7:21 AM
  • It was not installed on our machine either. We installed it last night and we'll see if anything changes.
    Friday, September 7, 2018 12:29 PM
  • This seems to have resolved our issue....
    Monday, September 10, 2018 1:00 PM
  • Yes, 3 days without any crash too... It smells good.

    Pascal.

    Monday, September 10, 2018 1:04 PM
  • Hello everybody,

    10 days without any crash :-)

    It was finally the right patch...

    Thank you Remo !


    Pascal.

    Monday, September 17, 2018 10:06 AM