Quantcast
Viewing all 3822 articles
Browse latest View live

How to Test UDP ldap port is working in ISA 2004

Dear All,

I was testing ports from my DC using PORTQUERY it display LDAP query to Port 389 is failed

My DC;s gateway is ISA server 2004 I have created an access rule allowing UDP netstat does not show UDP port 389

which causing Replication failure. windows 2008 R2 firewall is OK is any other thing to verify UDP 389 Port

God blessings...

RaSa


RaSa


TMG - RT streaming media

Does the TMG have any capability to optimize real time streaming media flows from the Internet? By that I mean if two or more people tuned in to the same real time streaming media would the TMG bring in only one flow from the Internet and then distribute it to the two or more clients?

Thanks, Boris

"Forefront TMG management cannot establish a connection with the Forefront TMG computer" error on Standalone Array Manager

I have 2 TMG servers with 2 network adapters. I followed next article to deploy Standalone array:

http://technet.microsoft.com/en-us/library/dd440981.aspx

After these task I have this error in Monitoring -> Configuration (Array Manager console) on the Array Managed server:

"Forefront TMG management cannot establish a connection with the Forefront TMG computer"

If I go to the Array Managed server console it is ok.

I have both servers added to "Managed Server Computers" and "Enterprise Remote Management Computers".

I need help to fix this issue.

I see this post:

http://social.technet.microsoft.com/Forums/en-US/Forefrontedgegeneral/thread/80f2a2f5-0b7e-4fc0-833f-a2e0e6651da5

But Do I need the cert if the server are domain members?

Also intra-array network adapter are required or recommended?

Thanks,


Dario Woitasen | MCSE Lync Server 2013 | MCITP: Enterprise Messaging Administrator 2007/2010, Lync Server 2010 Administrator

User Activity Report in TMG

HI,

Like Full report , is it possible to get a report for single user containing information or all site download , upload and traffic which http , https or ftp etc.

Regards

Usman Ghani


Usman Ghani - MCITP Exchange 2010

TMG 2010 in Primary and DR Site

We're looking to implement TMG 2010 with our upcoming Exchange 2010 upgrade.  Can I install and configure TMG in an array with 2 active nodes in our primary datacenter, and 1 passive node in our remote Disaster Recovery Datacenter?

ISA 2004 - open ports -what kind of rule?

We have SBS 2003 with ISA Server 2004. We are installing an appliance (Mail Archiving) that will have its own IP address on the network. The instructions say to open certain ports. For example:

Port: 123

Direction: In/Out

TCP: NO

UDP: YES

Would we create Access Rules for each port or do we create Server Publishing rules?  Basically the appliance needs to be able to be remotely supported and receive updates from Internet.

Thank you!

TMG routing help

Hi guys,

Actually, I'm deploying a new TMG server in my company and everything is working fine. However, a I have a small problem and until now, I couldn't solve it.

I have a link with a customer that works as described on picture below.

Image may be NSFW.
Clik here to view.

I need to reach the 10.x.x.x network, but I do not have any interface on my server in this network. So, I'd need to route any packages from my LAN (172.20.1.x) to the ISP firewall (192.168.1.x). However, this is not my default gateway, because this interface will used just to reach network 10.x.x.x.

How can I configure it on TMG?

Thanks a lot!


Lawrence Carvalho

isa server 2006 licence problem?

hi, "isa server 2006" I want to use. "server 2003" will build on. "If the server 2006" Can I continue to use after the expiration of three months of free usage rights.

3 months free use of the right, then what happens when I do not get the license? "ISA Server 2006" Can I continue using? My only "microsoft server 2003" got my license.

Thank you.

kendi imkanlarıyla atomu parçalayan adam!


Forefront TMG HTTPS to HTTPS bridging configuration,how to select a certificate file to authenticate to the SSL Web server?

Hi all

My environment is Forefront TMG 2010+ SharePoint 2010.

In this document:http://technet.microsoft.com/en-us/library/cc441474.aspx

HTTPS to HTTPS bridging: 

Image may be NSFW.
Clik here to view.
note
Note:
This scenario requires a server certificate on the Forefront TMG computer in order to authenticate it to the external client and requires a server certificate on the backend Web server in order to authenticate it to the Forefront TMG computer.
 

These two certificate should be same, or not?

when i select as following pic, I can not see my certificate file. but i have imported it to this path: Certificates(locate computer)-> Personal->Certificates. and in the HTTPS Listener's properties can see it.

 Anybody have idea about this?



Image may be NSFW.
Clik here to view.

Image may be NSFW.
Clik here to view.


Connection with SQL Server Management Studio through ISA 2004

I opened up TCP Port 1433 in ISA, but I still receive the following message when I try to connect to my outside SQL Server Database with SQL Server Management Studio.

Status: A packet generated on the local host was rejected because its source IP address is assigned to one network adapter and its destination IP address is reachable through another network adapter

Any ideas?


Facebook.com times out in Forefront TMG

I recently deployed Forefront TMG as my web access server. Users whose browser settings point to TMG as proxy server cannot access facebook. The connection times out with the error code 10060. All other websites, including social networking and https sites, remain accessible. I do not recall explicitly blocking access to facebook. I do not want to block access to any websites. How do I resolve this?

Security issue if I restart TMG services?

Hi

I faced high cpu problem on one of our TMG servers and it was caused by Windows Firewall service. After investigating I thought to restart the service and when you are going to restart it, it asks you: Do you want to restart these related services too (many TMG services). At this point I started to wonder what will happen if I restart TMG services. Is it a security risk? In worst case scenario there is network attack going on and if I restart all the services will it allow connections come through while TMG is restarting?

how HTTP request works

hello ,

I would like to know how HTTP requests works in details, where the request goes first to the TMG Firewall or DNS ?
Note  that I already configured the browser with proxy address and port 8080.

Thank you,

Tarek Faraj

Which product replace TMG functionality?

Hi,

I have several customers that wanted to deploy TMG Server as a web proxy/firewall back-end, but we all know that TMG is dieing? Which product offers exactly the same functionalities?


Cristian L Ruiz

TMG2010 - An LDAP server did not respond

Hi all,

I am having a problem where our TMG array will intermittently alert through SCOM that the LDAP servers have failed to respond.  We have 2 TMG servers running 2010 SP2 RU1, and each will occasionally flag an event 21286 that it could not contact the DC.  However, all functionality appears to be fine.

I have followed all the suggested steps for resolution in the SCOM alert and everything is already in order.  I have also confirmed that all is set up according to this guide: http://blogs.technet.com/b/keithab/archive/2013/05/01/3483834.aspx  The LDP utility allows me to connect to the DC mentioned in the alert without any problems, and yet we still get these alerts.

Any advice on how to get to the root of this would be much appreciated!  Failing that, if this is a "false" alert since everything appears to be working fine, is it safe to override the alert in SCOM?

Many thanks!
G


accessinf internet with schedule Error

hi
i have imported firewall policy from a tmg in domain x.com and imported theme to tmg in domain y.com

i have already created the users and schedules in the tmg in domain y.com an then import firewall policy

and clients in spesific schedule rule can not access to internet except clients in full time schedule
how can i fix this?

thanks for helping

https error

Hellopeople,

Currentlyneeded to usesome commands at TMGsincehadseveraloutingstohttps port,thenused the followingcommand:

Dimroot
DimtpRanges
DimnewRange
Setroot =CreateObject("FPC.Root")
SettpRanges=root.GetContainingArray.ArrayPolicy.WebProxy.TunnelPortRanges
SeptembernewRange=tpRanges.AddRange("SSL80",80,80)
tpRanges.Save

After thatI started gettingthe following messagesin the EventViewerSystem:

"The followingfatalalertwas generated:10.Theinternalerror stateis10.

Schannel
36888
error"

Mylogsystem ispacked with it.

Howeverif Iturn off theInspectionHttpserrortohappen,

Andalsositesthat begin withhttps,I cannotlonger accesselse orturning offhttpsinspection.

Howcan I fix this,is to undothe above commandfor port 80?

Thank you

TMG 2010 detected SYN attack and all Clent in Internal network can not access to Internet

Dear All

My system using TMG 2010 happen error " Forefront TMG detected a possible SYN attack and will protect the network accordingly" and all PC clent can not access to Internet.

There are some legal reasons for a clients which creates more connections at a timeto my customer fortheir work

Please help me how fix this problem.

internal ip 192.168.0.140 will have a look at an other internal PC with ip 192.168.0.119 to get a microsoft update.

Hi guys,

can someone explain what happend here?

I can not understand why the internal ip 192.168.0.140 will have a look at an other internal PC with ip 192.168.0.119 to get a microsoft update.

192.168.0.119 is NOT the default gateway (192.168.0.200

Fehlgeschlagener Verbindungsversuch     TMG200 08.05.2013 09:13:59
Protokolltyp: Webproxy (Forward)
Status: 10060 Ein Verbindungsversuch ist fehlgeschlagen, da die Gegenstelle nach einer bestimmten Zeitspanne nicht richtig reagiert hat, oder die hergestellte Verbindung war fehlerhaft, da der verbundene Host nicht reagiert hat.
Regel: Vollzugriff extern
Quelle: Intern (192.168.0.140:1072)
Ziel: Lokaler Host (192.168.0.119:80)
Anforderung: GET http://download.windowsupdate.com/v9/1/windowsupdate/redir/muv4wuredir.cab?1305080711
Filterinformationen: Req ID: 0b8cb8df
Protokoll: http
Benutzer: anonymous

Zusätzliche Informationen

    Client agent: Windows-Update-Agent
    Objektquelle: Internet (Quelle ist das Internet. Das Objekt wurde zum Cache hinzugefügt.)
    Cacheinformationen: 0x0
    Verarbeitungszeit: 63109 MIME type:

thanks in advanced

Richard

Fallback to basic / form based authentication when user certificate is expired

Hallo everybody,

I have currently published several sites in ForeFront TMG. The users access these sites with their smarphones (Android, iPhone). For authentication every user has an own certificate installed on its device.

TMG is configured to request client certificates for authentication. If there is no certificate present, the TMG asks for username and password. So far so good.

The only problem I have now, is that my certificates are valid for 1 year. If the certificate expires, the ForeFront TMG does not fall back to basic  authentication, because it still gets the certificate delivered. The user do not have any possibility to log in. It only works, if they manually delete the expired certificate.

It is not a problem yet, but in some months if somebody forgets to install a renewed cert on its device, it could lead to a situation where there is no login possible.

Can I somehow configure ForeFront in a way, that it tries basic authentication, after a certificate based authentication failed, because of expiry or revocation?

Thanks in advance

Mailer


Viewing all 3822 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>