Introduction Consider the scenario where we have URL Filtering enabled on TMG 2010 Server and it is not working. Troubleshooting A quick look at the Alerts section in TMG MMC shows: The failure is due to error: A certificate chain processed, but terminated in a root certificate which is not trusted by the trust…
Year: 2011
New WIKI article: Forefront Threat Management Gateway (TMG) 2010 Troubleshooting Survival Guide
As I mentioned in a previous post, Yuri Diogenes was working on a TMG troubleshooting survival WIKI page. The page is now ready and is available here. Reminder: WIKI pages are “live” documents and you are welcome to contribute edits to them. Knowing Yuri – you’re going to have a hard time finding a trick…
User Activity report for multiple users not working error 0xc0040432
The user activity report is a new feature of Forefront TMG SP1. I recently came across an issue where the customer was trying to run TMG user activity reports. When he used a single user (domainname\username) it rendered the report okay, but when we tried the same for 2 users (domainname\username1; domainname\username2) it gave the…
TMG Enhanced NAT – considerations when using the Default IP Address
With TMG we introduced a feature called “Enhanced NAT” (ENAT). ENAT enables you to configure the IP address you want to use as source IP when you NAT the traffic between 2 networks. The IP address has to be configured on the Interface, which is connected to the Destination Network, before you can select it…
TechNet Webcast: Talk TechNet with Keith Combs and Matt Hester – Episode 11: Yuri Diogenes on Forefront Threat Management Gateway (Level 200)
The tireless Yuri Diogenes was interviewed on Talk TechNet last week. If you did not get a chance to hear it live, a recording is available here. Yuri talked about Forefront TMG and answered a lot of questions. Highly recommended.
TMG 2010 SP1 and UAG 2010 SP1 are supported on Windows 2008 R2 SP1
Microsoft Windows 2008 Server R2 SP1 has recently been released. SP1 contains changes that are focused on supporting new types of hardware, adding support for several emerging standards, and addressing specific reliability, performance, and compatibility issues. SP1 changed areas relevant to TMG/UAG products are below: Area Changed Sub areas Networking: · DHCP · IPsec ·…
New WIKI Article by Yuri Diogenes–”Forefront TMG 2010 Survival Guide”
Hi all, Our very prolific Yuri Diogenes just contributed a new WIKI page called “Forefront TMG 2010 Survival Guide” (available here) which you may find interesting. The WIKI pages are “live” documents and we welcome additions, edits and contributions. Some information about using the WIKI initiative is available here: http://social.technet.microsoft.com/wiki/contents/articles/wiki-how-to-join.aspx http://social.technet.microsoft.com/wiki/contents/articles/wiki-getting-started.aspx http://social.technet.microsoft.com/wiki/contents/articles/wiki-how-to-contribute.aspx http://social.technet.microsoft.com/wiki/contents/articles/wiki-code-of-conduct.aspx …
Using Forefront TMG 2010 to Secure Access to Your Cloud Services
If you read the article Economics of the Cloud published last November on Microsoft on the Issues blog, you will see the that Microsoft analysis “uncovers economies of scale for cloud that are much greater than commonly thought”. As more and more business start to move to the cloud there is also the aspect of…
Connectivity verifier memory issues caused by optional update KB971737
Recently Microsoft Customer Service and Support have seen cases with the firewall process (wspsrv.exe) in ISA Server 2006 “leaking” memory until it reaches the 32-bit process limits or face too much memory fragmentation to continue working properly. On an ISA Server with high loads, memory fragmentation can always cause issues and that’s why we recommend…
CSS Forefront Edge Team is Hiring in US
The Microsoft TMG/UAG Server support team in US is looking to hire a Full Time Employee. If you’d be interested to come and work with us and learn more about TMG/UAG internals than you probably would anywhere else in the world ,then this might be the job for you. We’re looking for someone very experienced…