Quantcast
Channel: Forefront TMG and ISA Server forum
Viewing all 3822 articles
Browse latest View live

TMG - Forefront TMG cannot handle your request because the DNS quota was exceeded

$
0
0

All the clients in the network are recieving errors:

Forefront TMG cannot handle your request because the DNS quota was exceeded

unable to RDP to TMG server which holds the public DnS.

We needed to reboot the server.

How to solve this please?


bostjanc


TMG - disabling rc4 128 ciphers

Forefront TMG disconnected a non-TCP connection from DOMAIN CONTROLLER

$
0
0

We recieve a lot of warnings in event viewer/app on TMG server:

Forefront TMG disconnected a non-TCP connection fromDOMAIN CONTROLLER

We already added this domain controller on TMG's Flood Mitigation IP Exceptions list but that did not help.

Those warning events are still shown on Event Viewer/app on TMG side.

Any hints how to solve this problem please?

with best regards


bostjanc

Forefront TMG with Google Chromecast (UPNP discovery)

$
0
0

We are a small business and so far we have been using Forefront TMG 2010 (in a simple LAN-DMZ-WAN 3-legged configuration) with great success.

Recently we added a Google Chromecast to the TV/Monitor in our meeting room. The Chromecast device itself works great but other devices on the same LAN cannot discover it.
It's my understanding that Chromecast uses UPNP SSDP discovery protocol which, by default, is being blocked by Forefront.
And In fact in the log we see an endless stream of the following errors:

Log type: Firewall service 
Status: An ingoing packet was dropped because its destination address does not exist on the system, and no appropriate forwarding interface exists.  
Rule: None - see Result Code 
Result Code: 0xc0040050 FWX_E_TCPIP_DROP_IP_NOT_LOCALLY_DESTINED
Source: Internal (172.16.8.76:60164) 
Destination: UPNP (239.255.255.250:1900) 
Protocol: Unidentified IP Traffic (UDP:1900) 

In addition to the existing "Internal" interface (address range 172.16.8.0-172.16.8.255) I created a new internal "UPNP" interface with the address range: 239.255.255.0-239.255.255.255 and a "route" relationship between the "Internal" and "UPNP" interfaces.
I also added firewall policy rules to give full access to each other.

Unfortunately Chromecast discovery is still not working.

Any suggestion how to resolve this issue and let Forefront allow UPNP SSDP discovery?

Thanks.


---Mirco.



Error Code 407 Proxy Authentication required

$
0
0

Hi everyone,

i am using Tmg 2010 in my network and also using Fortinet firewall.

i facing problem since last month the Tmg deny firewall to access internet. the Tmg asking authentication to allow access internet

already set user name and password to firewall(done by fortigate team support)but still facing problem.

i hope one help me to avoid this problem.

thanks in advance

Dropbox not running in domain via TMG 7.0

$
0
0

i am unable to use dropbox on WORKGROUP computer in a domain network.

we using MS Forefront TMG 7.0.9.193.500 and tmg client on domain computers. so dropbox working fine on tmg client PCs, but not connecting on workgroup PCs , i tried with no proxy, auto detect and manual proxy for dropbox but didn't worked .

i also create a rule on TMG which allowed all domains, URLs of dropbox.com .. but nothing working for me.

advance thanks for precious suggestions.

Dropbox on ISA2004

$
0
0

Hi All,

we are running ISA 2004 proxy, cannot connect to dropbox through the proxy. we can connect to dropbox directly without using proxy. please advise what configuration shell i make to allow dropbox through our ISA


Virgo

Get upstream proxy FQDN in Web Filter plugin

$
0
0
In my ISA/TMG web filter plugin I need to add a header with the upstream proxy FQDN as a value. I supposed  GetServerVariable function should return the upstream proxy FQDN for SERVER_NAME property. However SERVER_NAME property contains IP of ISA server, not upstream proxy. Is there a way to get the correct upstream proxy FQDN for a web filter plugin?

FF TMG 2010 on Server 2012

$
0
0

Has anyone tried successfully installing Forefront TMG 2010 on Windows Server 2012?

I tried but failed, it complained about unable to add roles and features.


Valuable skills are not learned, learned skills aren't valuable.


allow access to a specific ip in tmg 2010

$
0
0
I create a role to block a site in my Network and now i want to allow some users (using there IP Address) to access that site. but don`t understand how to allow them, kindly help me.

Yellow Triangle in Windows 7

$
0
0
I am using TMG 2010 and the issue is that when i am adding a Proxy Server IP to any win7 client there`s a Yellow Triangle shown and  i want to remove that, am searching a lot but no result found so kindly help me to remove this triangle.

Dropbox Desktop application not running in domain via TMG 7.0

$
0
0

i am unable to use dropbox on WORKGROUP computer in a domain network.

we using MS Forefront TMG 7.0.9.193.500 and tmg client on domain computers. so dropbox working fine on tmg client PCs, but not connecting on workgroup PCs , i tried with no proxy, auto detect and manual proxy for dropbox but didn't worked .

i also create a rule on TMG which allowed all domains, URLs of dropbox.com .. but nothing working for me.

advance thanks for precious suggestions.

ISA Custom Forms

$
0
0

Hello,

We have a problem creating custom forms on ISA 2006. The default ones work fine but if I copy the 'ISA' folder for example (under CookieAuthTemplates), name it something else, then set the new name either on the listener or the publishing rule we get the following error when accessing the pages -

Error Code: 500 Internal Server Error. The data is invalid. (13)

Has anyone seen this before?

I've seen a few people talking about disabling HTTP compression but this doesn't seem to have made any difference.

Thanks in advance,
Chris

Forefront Tmg 2010 and NetBios broadcasts. How to enable it from LocalHost to Internal and vise versa ?

$
0
0

There is Windows 2008 R2 with Tmg 2010 SP2 installed at it.

As I saw at many articles and found out from Tmg log that broadcast UDP packets even outgoing from LocaHost (server where Tmg installed) with source IP = IP server to 192.168.0.255 address is denied even outgoing, that is:

IP server -> 192.168.0.255 is denied

I think, packets from every internal nework client to 192.168.0.255 is denied also (I didn' t see such line at log) .

How is to enable broadcast for Internal that in particular NetBios broadcast packets could be allowed (accepted) as from LocalHost as to LocalHost (at least from LocalHost) ?

It would be appreciated if some registry parameter would present to enable/disable broadcast.

And what the latest Tmg version of SP supports of broadcast ?


How we can check Microsoft ISA Server 2006 Version: 5.0.5723.514 is standard edition or enterprise edition

$
0
0

hi,

we are using  Microsoft  "ISA Server 2006 .Version: 5.0.5723.514".

But how we can check it is ISA Server 2006 standard edition or a enterprise edition.

And how we can check its END OF LIFE AND   END OF SUPPORT dates.

thanks and regards,

Ravi


ISA 2006 failed to install ADAM on server 2003 EE

$
0
0
Dear Expert Please resolve the Title matter I am trying to install ISA 2006 on Win2003 EE during install I am getting error Setup Failed to Install ADAM 0x80070001

all microsoft sites name not resolved

$
0
0

Hi All,

I have a ISA 2006 server.I can browse all the website except microsoft sites (like: microsoft.com, support.microsoft.com etc)

the web page shows err_name_not_resolved 

the details shows dns lookup failed .... 

I haven't configured DNS in the ISA .

i tried to monitor the logs ... it dosen't show any rules blocking the sites .....
help help 

Thakyou

Forefront TMG and domain controller configuration in Hyper-V

$
0
0
Hello,

I have a server i have install on it hyper-v then 2 windows server 2008 R2:
one for tMG and the second for the domain controller.
on the domain controller have connect it to the internal network with the following information:
ip: 192.168.0.4 , gateway: nothing, DNS: 192.168.0.4 
and on the domain controller i have create the dns and the dhcp to send the ip to the others internal device that we need to connect.
for the tmg on hyper-v i have connect it to the internal and external network:
internal :
ip: 192.168.0.3 , gateway: nothing, dns: 192.168.0.4 
external :
ip: 192.168.10.3 , gateway: 192.168.10.250 , dns: nothing
the external network has internet connection.

till now i can't access the internet on the device connected to the domain.
if they are any clear documentation about how to manage this.
the goal is to control the internal user using the tmg and the domain controller

thanks in advance.

problem in VPN connection acess in TMG

$
0
0

I have installed TMG Server in head office, after configuring TMG, everything is working properly like emails, internet acess, except head office users are unable to connect with remote site ERP Server using VPN dial up connection.
TMG is blocking VPN traffic, users are unable to dial VPN connection to acess remote office ERP Server.
I have made rule for this issue.
Protocol = All Outbound Traffic / VPN Protocol (PPTP-L2TP)
Action = Allow
Source = Local host and Internal Host
Destination = Remote TP-Link Router Static IP (232.125.65.98)
Users = All

After activating the above rule, while dialing VPN Connectiopn from head office, users get the following errors.
Any one please give me some suitable idea to resolve the issue.


Error 800: The remote connection was not made because the attempted VPN tunnels failed. the VPN server might be unreachable. If this connection is using IPSEC or L2TP tunnel, the security parameters required for IPSEC negotiation might not be configured properly.

RDP session is refused by TMG

$
0
0

We would like to access Azure host(Public) through TMG.

1.Source Subnet is ok;

2.All outbound is enabled.

3.Azure host ip address is correct.

4.Installed TMG client application on laptop.

5.when we try to access the Azure host ip address, the error message is present.

6. Based on above information, i captured netmon trace on Laptop and found the clue. Is there anyone can let us know why this Connection refusedby TMG? Thanks. 

1610:18:39 AM 9/3/20158.8922839mstsc.exeClientTMGTCPTCP:Flags=......S., SrcPort=56750, DstPort=1745, PayloadLen=0, Seq=2367321505, Ack=0, Win=8192 ( Negotiating scale factor 0x8 ) = 8192{TCP:5, IPv4:4}
1710:18:39 AM 9/3/20158.8933019mstsc.exeTMGClientTCPTCP:Flags=...A..S., SrcPort=1745, DstPort=56750, PayloadLen=0, Seq=1323644357, Ack=2367321506, Win=8192 ( Negotiated scale factor 0x8 ) = 2097152{TCP:5, IPv4:4}
1810:18:39 AM 9/3/20158.8935506mstsc.exeClientTMGTCPTCP:Flags=...A...., SrcPort=56750, DstPort=1745, PayloadLen=0, Seq=2367321506, Ack=1323644358, Win=257 (scale factor 0x8) = 65792{TCP:5, IPv4:4}
1910:18:39 AM 9/3/20158.9273484mstsc.exeClientTMGRWSRWS:Channel setup request (TMG compatible) for mstsc.exe as Steven_Song on PRCSGI1497L version 6.1.7601{RWS:6, TCP:5, IPv4:4}
2010:18:39 AM 9/3/20158.9285267mstsc.exeTMGClientRWSRWS:Channel setup response to mstsc.exe (TMG compatible), authentication not required; encryption not required{RWS:6, TCP:5, IPv4:4}
2110:18:39 AM 9/3/20158.9297390mstsc.exeClientTMGRWSRWS:{RWS:6, TCP:5, IPv4:4}
2210:18:39 AM 9/3/20158.9297390mstsc.exeClientTMGTCPTCP:[Continuation to #21]Flags=...AP..., SrcPort=56750, DstPort=1745, PayloadLen=399, Seq=2367322405 - 2367322804, Ack=1323644639, Win=256 (scale factor 0x8) = 65536{TCP:5, IPv4:4}
2310:18:39 AM 9/3/20158.9308009mstsc.exeTMGClientTCPTCP:Flags=...A...., SrcPort=1745, DstPort=56750, PayloadLen=0, Seq=1323644639, Ack=2367322804, Win=257 (scale factor 0x8) = 65792{TCP:5, IPv4:4}
2410:18:39 AM 9/3/20158.9308854mstsc.exeClientTMGRWSRWS:0x2 Connect v12 request from mstsc.exe to 40.113.157.119/3389; client will send from 10.158.129.2/56751{RWS:6, TCP:5, IPv4:4}
2510:18:39 AM 9/3/20158.9320289mstsc.exeTMGClientRWSRWS:0x2 Error to mstsc.exe for Connect v12(40.113.157.119); (10061); Connection refused{RWS:6, TCP:5, IPv4:4}
2710:18:39 AM 9/3/20159.1370816mstsc.exeClientTMGTCPTCP:Flags=...A...., SrcPort=56750, DstPort=1745, PayloadLen=0, Seq=2367323085, Ack=1323644920, Win=257 (scale factor 0x8) = 65792{TCP:5, IPv4:4}

Have a nice day!

Rgds

Steven

Viewing all 3822 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>