Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

TMG 2010 Firewall prevents array servers upgrading - Help!!!

6 views
Skip to first unread message

Tucker

unread,
Nov 11, 2010, 4:20:29 AM11/11/10
to
Hi all,

The following my configuration:

An Enterprise Configuration Store, running only ADAM, joined to a
domain and two array servers, running firewall services in a
workgroup. Configuration process is authenticated by SSL certificates
applied by CertTool.exe and absolutely still valid.

Issue:

Configuration update from ECS to Firewall servers worked for a couple
of months or more, but now it does not work anymore.
I discovered that when I stop TMG firewall service on array servers
the configuration update happens regularly (WORKS FINE WITH NO
FIREWALL) so I'm sure the SSL authentication process is rightly
configured.
When the firewall service runs on array servers, they keep to try the
update process showing the usual "updating" icon with a computer and
two opposite blue arrows.

What I tried:
I tried to create a rule that allow full communication among the three
machines involved, stopped firewall services on array members,
performed a configuration update successfully ended and re-enabled
firewall services. When firewall services was down all the
configuration changes was correctly updated to the array members,
since the firewall services start the update process stops working and
the configuration status remain pending to "Updating"

Telnet over ports 2171, 2172 works fine from array members and ECS
even while firewall services run.
LDP.exe connections work fine even with firewall services running.
System policies are configured for allowing configuration updates over
ECS.


Please what can I try now?
Help me please...

Thanks in advance

Tucker

unread,
Nov 11, 2010, 12:10:39 PM11/11/10
to
Found a workaround. Firewall service have has to start a little late
than the other tmg-related services expecially the job scheduler
service. On Windows Server 2008 R2, but I don't know if also on
Windows 2008 Sp2, the latter service takes a long time to start, and
to me this is the problem.
Otherwise the product, even updated up to SP1+Update1 is heavily
bugged, a lot of staff must be adjusted to work.
Actually I'm a little disappointed with the product, had less problems
with ISA 2006.
0 new messages