<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security for a day &#187; ISA/TMG</title>
	<atom:link href="http://www.chris-mohan.com/category/isa/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chris-mohan.com</link>
	<description>Securing Windows networks or giving it a go in Australia...</description>
	<lastBuildDate>Sat, 31 Dec 2011 12:54:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The Curious case of licensing TMG’s Web Protection Services Licensing</title>
		<link>http://www.chris-mohan.com/2011/04/the-curious-case-of-licensing-tmg%e2%80%99s-web-protection-services-licensing/</link>
		<comments>http://www.chris-mohan.com/2011/04/the-curious-case-of-licensing-tmg%e2%80%99s-web-protection-services-licensing/#comments</comments>
		<pubDate>Fri, 08 Apr 2011 05:46:50 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[Forefront]]></category>
		<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=838</guid>
		<description><![CDATA[Microsoft’s Threat Management Gateway (TMG) comes with a 120 day trial of two subscription-based features, wittily known  as Forefront TMG Web Protection Services (WPS). These features are URL Filtering (URLF) which is a form of web content filtering and Anti-Malware or Enhanced Malware Protection (AM or EMP) that scans inbound HTTP traffic downloads. &#160; We [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft’s Threat Management Gateway (TMG) comes with a 120 day trial of two subscription-based features, wittily known  as Forefront TMG Web Protection Services (WPS).</p>
<p>These features are URL Filtering (URLF) which is a form of <a href="http://blogs.technet.com/b/isablog/archive/2009/06/10/url-filtering-is-here.aspx">web content filtering</a> and Anti-Malware or <a href="http://technet.microsoft.com/en-us/library/dd253247.aspx">Enhanced Malware Protection</a> (AM or EMP) that scans inbound HTTP traffic downloads.</p>
<p><a href="http://www.chris-mohan.com/wp-content/uploads/2011/04/TMG-mal-insped.bmp"><img class="aligncenter size-full wp-image-840" title="TMG malware inspection license option" src="http://www.chris-mohan.com/wp-content/uploads/2011/04/TMG-mal-insped.bmp" alt="" /></a></p>
<p>&nbsp;</p>
<p>We have an Enterprise Agreement (EA) which covers having the two features  so I expected to find the key in our License portal. No, that’s too obvious. It turns out that I needed to enter our actual Enterprise Agreement key. The first seven digits of the EA needs to be popped in to the TMG server field in the picture above then Ms&#8217; trusts you to enter in the right date your EA expires. That’s it.</p>
<p>Finding this out took quite a bit of time, numerous emails and careful explanation to people what the heck was WPS in TMG. Finally this link from Ms <a href="http://blogs.technet.com/b/isablog/archive/2010/02/02/forefront-tmg-2010-web-protection-services-licensing.aspx">turned up</a></p>
<p><a href="http://blogs.technet.com/b/isablog/archive/2010/02/02/forefront-tmg-2010-web-protection-services-licensing.aspx"></a><br />
Had I found this at the start, well, it would have taken two minutes rather than two weeks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2011/04/the-curious-case-of-licensing-tmg%e2%80%99s-web-protection-services-licensing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When ISACTRL ruins your day on a TMG</title>
		<link>http://www.chris-mohan.com/2011/01/when-isactrl-ruins-your-day-on-a-tmg/</link>
		<comments>http://www.chris-mohan.com/2011/01/when-isactrl-ruins-your-day-on-a-tmg/#comments</comments>
		<pubDate>Tue, 04 Jan 2011 12:55:54 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/2011/01/when-isactrl-ruins-your-day-on-a-tmg/</guid>
		<description><![CDATA[While tinkering with a TMG issue, a TMG server stopped working as expected. The symptoms I observed were when rebooting the TMG server I had to wait TWENTY minutes of looking at Applying Computer Settings screen before I could log in, only to find out that four out of the five TMG services hadn&#8217;t started. The [...]]]></description>
			<content:encoded><![CDATA[<p>While tinkering with a TMG issue, a TMG server stopped working as expected. The symptoms I observed were when rebooting the TMG server I had to wait TWENTY minutes of looking at Applying Computer Settings screen before I could log in, only to find out that four out of the five TMG services hadn&#8217;t started.</p>
<h4>The event logs had these errors:</h4>
<p style="padding-left: 30px;">- The following service is taking more than 15 minutes to start and may have stopped responding: Microsoft Forefront TMG Control</p>
<p style="padding-left: 30px;">- The following service is taking more than 15 minutes to start and may have stopped responding: SQL Server Reporting Services (ISARS)</p>
<p style="padding-left: 30px;">- The Microsoft Forefront TMG Control service terminated with service-specific error The wait operation timed out</p>
<p style="padding-left: 30px;">- The SQL Server Reporting Services (ISARS) service hung on starting.</p>
<p style="padding-left: 30px;">- The Microsoft Forefront TMG Firewall service depends on the Microsoft Forefront TMG Control service which failed to start</p>
<p style="padding-left: 30px;">- The Microsoft Forefront TMG Managed Control service depends on the Microsoft Forefront TMG Control service which failed to start</p>
<p style="padding-left: 30px;">- The Microsoft Forefront TMG Job Scheduler service depends on the Microsoft Forefront TMG Control service which failed to start</p>
<p>This meant the TMG wasn&#8217;t a firewall anymore and need all the TMG services to be started to be useful and work correctly.</p>
<p>This was rather annoying, but since I was on the phone to Microsoft on another TMG call, they identified this as a known problem and offered this fix; At the administrative command prompt type:</p>
<p><strong>sc config isactrl depend= RasMan/SSTPSVC/FwEng/ISASTG/bfe/mpssvc/HTTP</strong></p>
<p>- then reboot the server.</p>
<p>The server took its normal two minutes to get to the log in screen and the TMG services were running normally. Marvellous.</p>
<p>Well that was all well and good, but I like to know what this command meant and did.</p>
<p>The <a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/sc.mspx?mfr=true">sc command</a> invokes the Service Controller and the config part denotes which service (isactrl) to work with but it&#8217;s the depend= which brings the magic. Typing sc qc isactrl on a working TMG show these services (RasMan, SSTPSVC, FwEng, ISASTG, bfe, mpssvc and HTTP) are dependencies of the ISACTRL service and that what the depend= means – dependencies that have to be running first. So running this command forces the TMG to waiting for certain services to start, in this case RasMan SSTPSVC FwEng ISASTG bfe mpssvc HTTP before starting the TMG Control service.</p>
<h2>Footnote</h2>
<p>After adding another patch to the TMG you have to <strong>run SC the command again</strong> as it seems to reset the dependancies.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2011/01/when-isactrl-ruins-your-day-on-a-tmg/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TMG versus FTP</title>
		<link>http://www.chris-mohan.com/2010/12/tmg-versus-ftp/</link>
		<comments>http://www.chris-mohan.com/2010/12/tmg-versus-ftp/#comments</comments>
		<pubDate>Thu, 16 Dec 2010 06:17:02 +0000</pubDate>
		<dc:creator>ChrisM</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=788</guid>
		<description><![CDATA[The great thing about any new or updated firewall is the coders understand the protocols and processes that little bit more. This means the stuff that worked on the old version might now not work on the new one. This is very much the case on moving from ISA to TMG &#8211; especially for FTP. [...]]]></description>
			<content:encoded><![CDATA[<p>The great thing about any new or updated firewall is the coders understand the protocols and processes that little bit more. This means the stuff that worked on the old version might now not work on the new one. This is very much the case on moving from ISA to TMG &#8211; especially for FTP.</p>
<p>This has created  issues with Active FTP and FTP over HTTP which is why this piece is now here to help others avoid similar learning pains.</p>
<h2>Active FTP</h2>
<p>TMG blocks Active FTP by default, which is a good thing as Active FTP is bad.  Well, RFC 959 doesn’t actually define Active FTP as bad,  but the way it works mean the client FTP firewall has to open up a large number of ports and keep track of them inbound from the FTP server. So using Passive FTP means  it’s good for the TMG admin with the FTP clients and possibly very painful to the admin hosting  the FTP site, but we’re all about defense here. Nice explanation here of the two FTP transfers <a href="http://www.linuxhowtos.org/Misc/ftpmodes.htm">here</a></p>
<p>The only problem is that there’s a list of Ms products that use Active FTP as the client by default. The most annoying of which is the built in FTP.exe client on every windows machine. This is extremely painful as there is no way to force this to run in passive mode (Don’t get me started on the quote pasv option in Ms’ FTP.exe debacle – why tell the server to use passive FTP and then, as the client, NOT be able to use passive FTP in the first place!)</p>
<p>SQL Server Integration Service (SSIS) and BizTalk also use Active FTP by default but are easy to flip over to passive FTP.</p>
<p>For those zany folks that have to FTP from the command line I really like <a href="http://www.ncftp.com/">ncftp</a>. NCftp client is a free piece of software ported from the *nix world, it has a wonderful <a href="http://www.ncftp.com/download/">.msi format</a> that is easy to deploy to Windows systems. Running commands from a .bat file is as easy as this:</p>
<p>ncftpput -a -u username -p password ftp.site.com . c:\downloads\test.txt</p>
<p>The . (period) after ftp.site.com represents the current directory on the <em>FTP server</em>, in this case the default directory for the username used to log in with.</p>
<p>Uploads local file c:\downloads\test.txt  to the current FTP directory on ftp.site.com after login</p>
<p>ncftpget a -u username -p password ftp.site.com . &#8220;D:\Server\somewhere\weird folder\&#8221; topsecret.*</p>
<p>Downloads remote files topsecret.* from  ftp.site.com after login  to &#8220;D:\Server\somewhere\weird folder\&#8221;  </p>
<p>The quotes are only used as a space character is used in the folder path. The . (period) after ftp.site.com represents the current directory on the <em>FTP server</em>, in this case the default directory for the username used to log in with.</p>
<p>Plenty of <a href="http://www.ncftp.com/ncftp/">documentation</a> so if you decide to use it, drop some coins in via their paypal donate  button.</p>
<h4 style="text-align: center;">Can’t get away from Active FTP?</h4>
<p>For those stuck in the hell of using Active FTP for a client to an Active FTP site Yuri Diogenes has written a great piece on how to use the application filter to allow Active FTP <a href="http://blogs.technet.com/b/yuridiogenes/archive/2010/03/16/error-502-active-ftp-not-allowed-when-trying-to-list-files-in-a-ftp-session-behind-forefront-tmg-2010.aspx">here</a> so I won’t repeat his instructions.</p>
<h2>FTP over HTTP</h2>
<p>Back to FTP over HTTP in TMG. For those wondering what this is open up your web browser and type in <a href="ftp://ftp.microsoft.com/">ftp://ftp.microsoft.com</a> It presents a web view of the ftp site – FTP over HTTP in its full glory.</p>
<p>In ISA have a rule allowing FTP and HTTP meant everything worked,  but in TMG they add in the new protocol FTP over HTTP. If you have staff using web browsers to download FTP through the browser then add in or update your FTP allow rule to include the protocol FTP over HTTP.  That should keep everyone happy.</p>
<h3>Why isn’t my FTP over HTTP rule working</h3>
<h4>- One firewall too many</h4>
<p>You’ve changed your TMG rule but you still get an Error Code 10061 web page from TMG when using FTP over HTTP for any site. For example, in the browser goes <a href="ftp://ftp.microsoft.com/">ftp://ftp.microsoft.com</a> but this appears:</p>
<p><strong>Technical Information (for support personnel)</strong></p>
<ul>
<li>Error Code 10061: Connection refused</li>
<li>Background: The server you are attempting to access has refused the connection with the gateway. This usually results from trying to connect to a service that is inactive on the server.</li>
<li>Date: 6/6/666 1:23:45 PM [GMT]</li>
<li>Server: IloveTMG.honest.com</li>
<li>Source: Remote server</li>
</ul>
<p>Now if you have:</p>
<p>A)      use multiple IP addresses on your external interface</p>
<p>B)      Have set the internal to External Network Rule to use a certain NAT IP address</p>
<p>C)      Have a edge firewall/router blocking traffic from certain IP addresses*</p>
<p>You’re problem is the TMG misbehaving and edge firewall device doing its job.</p>
<p>Here’s an example of what the problem is:</p>
<p>I have 192.168.1.66 defined as the IP address the outside world will see from the TMG, despite have twenty other IP addresses on the same external interface. This is defined in the Network Rule tab of the Networking section of the TMG interface.</p>
<p><a href="http://www.chris-mohan.com/wp-content/uploads/2010/12/TMG_Network_Rule.jpg"><img class="aligncenter size-full wp-image-798" title="TMG_Network_Rule" src="http://www.chris-mohan.com/wp-content/uploads/2010/12/TMG_Network_Rule.jpg" alt="" width="735" height="55" /></a></p>
<p>With a network sniffer, such as Netmon or Wireshark, installed on the TMG server(see below) and listening on the external interface for traffic going to the internet, the TMG uses 192.168.1.66, as it supposed to.</p>
<p>Now connect to <a href="ftp://ftp.microsoft.com/">ftp://ftp.microsoft.com</a> from a browser and it uses a different IP address (192.168.1.59 in this example)</p>
<p><a href="http://www.chris-mohan.com/wp-content/uploads/2010/12/Wireshark_snip.jpg"><img class="aligncenter size-full wp-image-799" title="Wireshark_snip" src="http://www.chris-mohan.com/wp-content/uploads/2010/12/Wireshark_snip.jpg" alt="" width="1193" height="214" /></a></p>
<p>Feel free to rush to your test lab, try this out for yourself and see it with your own eyes. I’ll wait until you’re back.</p>
<h3>But why? WHY?</h3>
<p>TMG uses  the IP address chosen by Window 2008 TCP/IP stack to pushes out FTP over HTTP rather than the IP address specified in the Network Rule. So it’s Windows 2008 TC/IP stack that’s to blame, rather than poor old TMG, although TMG should really be in full control, so bad TMG! There’s a number of KB’s and articles explaining how Windows 2008 deals with multiple IP addresses.</p>
<h3>So what’s the fix?</h3>
<p>Easy, but crap security option is to allow FTP out on that IP address (192.168.1.59 in this example) on the external firewall.</p>
<p>I have a request in with Microsoft’s TMG team to explain and hopefully fix this odd behaviour, so when I get a response I’ll update this post</p>
<p>*Option C is pretty common to have a hardware appliance (Cisco, Checkpoint , F5, Sonicwall, etc.) sitting on the edge of the network between the TMG and the raw internet pipe (router, modem or USB device uplink to the <a href="http://en.wikipedia.org/wiki/Internet_service_provider">ISP</a>) I like have a box in front of the TMG as it stops the random junk traffic from hitting the TMG and provides another layer of defense.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2010/12/tmg-versus-ftp/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>IAG&#8217;s SSL Wrapper fails for Java</title>
		<link>http://www.chris-mohan.com/2009/09/iags-ssl-wrapper-fails-for-java/</link>
		<comments>http://www.chris-mohan.com/2009/09/iags-ssl-wrapper-fails-for-java/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 01:50:39 +0000</pubDate>
		<dc:creator>Chris Mohan</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=461</guid>
		<description><![CDATA[After doing some normal patching updates on the IAG and client machines, I suddenly had the problem when trying to connect to a Java based application. The SSL wrapper screen appeared but after a minute an error would appear. The app wasn&#8217;t working. This isn&#8217;t good as The fix turnd out to be quick and [...]]]></description>
			<content:encoded><![CDATA[<p>After doing some normal patching updates on the IAG and client machines, I suddenly had the problem when trying to connect to a Java based application. The SSL wrapper screen appeared but after a minute an error would appear. The app wasn&#8217;t working. This isn&#8217;t good as</p>
<p>The fix turnd out to be quick and easy:</p>
<p>In the IAG  configuration app, in the URL filter change InternalSite_Rule28 to Ignore and replace InternalSite_Rule29 URL to /internalsite/com/whale/sslvpnclient/whalesslvpnclient/class.class</p>
<p>Getting to this was a hour of head scratch, searching and playing. This is my journey to that two second fix.</p>
<p>I fired up the IAG Web monitor and noticed these errors:</p>
<p>Severity     ID       Type<br />
Warning   55     Parameters not Allowed with URL Security portal (S)</p>
<p>Request failed, URL is not allowed to contain parameters.</p>
<p>Trunk: portal; Secure=1;</p>
<p>Application Name: Whale Internal Site; Application Type: InternalSite; Source IP: x.x.x.x; Method: GET; URL: /InternalSite/applet/sslvpnclient.jar?version-id=3.7.0.14.</p>
<p>Severity     ID       Type</p>
<p>Warning     67     URL Path not Allowed Security csrportal (S) Request failed, the URL contains an illegal path.</p>
<p>Trunk: portal; Secure=1;</p>
<p>Application Name: Whale Internal Site; Application Type: InternalSite; Rule: Default rule; Source IP: x.x.x.x; Method: GET; URL: /InternalSite/com/whale/sslvpnclient/whalesslvpnclient/class.class.</p>
<p>I knew I  had not changed on the rules or configuration.</p>
<p>Clicking on the first error of ID 67  popped up this:</p>
<p>Warning #67: URL Path not Allowed</p>
<p>Symptoms</p>
<p>A remote user requests  a page. The request is denied, and the following message is displayed in the  browser window: &#8220;You have attempted to access a restricted URL. The URL you are  trying to access contains an illegal path.&#8221;</p>
<p>Cause</p>
<p>The path of the  requested URL was rejected by the URL Inspection engine.</p>
<p>Resolution</p>
<p>Take the following  steps in the Configuration program:</p>
<p>1. Open  the Advanced Trunk Configuration window, and select the URL Set tab.</p>
<p>2. Do one of the  following, depending on the rule that caused the failure, as specified in the  &#8220;Description&#8221; filed of the message:</p>
<p><span>• </span>If the rule that caused the failure is  &#8220;Default rule&#8221;, use the URL List to add a new rule, or edit one of the existing  rules, so that the requested URL is allowed.</p>
<p style="letter-spacing: -0.01em; color: black; text-decoration: none;"><span>• </span>If the failure was caused by an existing  rule, and the name of the rule is specified in the message’s &#8220;Description&#8221;  field, access the rule in the URL List. In the &#8220;URL&#8221; column, edit the path of  the URL.</p>
<p>Cracking open the IAG configuration tool and searching the URL List I  found InternalSite_Rule29 was very slightly different to the one in the failed error. I swapped it from</p>
<p>/InternalSite/com/whale/sslvpnclient/whalesslvpnclient.class</p>
<p>to</p>
<p>/internalsite/com/whale/sslvpnclient/whalesslvpnclient/class.class</p>
<p>Saved the configuration and tried the Java app again. Still failed.</p>
<p>After a bit of head scratching I found this <a title="IAG SSL Wrapper fix" href="http://forums.forefrontsecurity.org/?g=posts&amp;m=553" target="_blank">post</a> from the excellent <a title="forefrontsecurity.org" href="www.forefrontsecurity.org" target="_blank">www.forefrontsecurity.org</a></p>
<p>InternalSite_Rule28 (/internalsite/applet/(sslvpnclient|detectjava|microsoftclient|oesislocal|runtimeelevator|agent_win_helper|agent_mac_helper|agent_lin_helper)\.jar)<br />
changed Parameters value Reject to: Ignore</p>
<p>Basically this stops the checking on the detection agents and allows the Java applet to do it job.</p>
<p>Another Hum Ho moment.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2009/09/iags-ssl-wrapper-fails-for-java/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blocking web sites on ISA 2006</title>
		<link>http://www.chris-mohan.com/2009/07/blocking-web-sites-on-isa-2006/</link>
		<comments>http://www.chris-mohan.com/2009/07/blocking-web-sites-on-isa-2006/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 05:04:05 +0000</pubDate>
		<dc:creator>Chris Mohan</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=392</guid>
		<description><![CDATA[A quick and simple ISA rule to block dangerous web sites and URLs Overview: Create a URL set of all sites and block them. In this case I want to stop users being re-directed to the malware sites of the day. The sites I want to blocked are taken from the Internet Storm Center story [...]]]></description>
			<content:encoded><![CDATA[<p>A quick and simple ISA rule to block dangerous web sites and URLs</p>
<p>Overview: Create a URL set of all sites and block them.</p>
<p>In this case I want to stop users being re-directed to the malware sites of the day. The sites I want to blocked are taken from the Internet Storm Center story on Internet Explorer Zero-day <a title="IE 0day exploit domains" href="http://isc.sans.org/diary.html?storyid=6739" target="_blank">here</a></p>
<p>A quick way to do this:</p>
<p>1)      Create a URL set call Malware – Blocked Sites and add in one URL i.e. <a href="http://www.badtest.com/">www.badtest.com</a> to blocked sites</p>
<p>2)      Export the URL Set to a XML file Blocked.xml.</p>
<p>3)      Dump the list of bad web sites in to a table or excel.</p>
<p>4)      Pop  &lt;fpc4:Str dt:dt=&#8221;string&#8221;&gt; and &lt;/fpc4:Str&gt; around each URL<br />
i.e. &lt;fpc4:Str dt:dt=&#8221;string&#8221;&gt;http://Badsite.bad.com&lt;/fpc4:Str&gt;</p>
<p>5)      Open Blocked.xml in a text editor, such as notepad.</p>
<p>6)      Copy all of the edited entries in to the exported URL sites under the place holder URL <a href="http://www.badtest.com/">www.badtest.com</a>, that’s under &lt;fpc4:URLStrings&gt;, and save the file.</p>
<p>7)      Import the Blocked.xml in to the URL set: Malware – Blocked Sites.</p>
<p>8)      All the sites are now listed in alphabetical order in the URL set.</p>
<p>9)      Create a deny rule for all protocols from Internal to Malware – Blocked Sites URL set.</p>
<p>10)   Press the Apply button.</p>
<p>This will block and log access to those malicious/dangerous web sites.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2009/07/blocking-web-sites-on-isa-2006/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Kicking off the MCITP:Enterprise Study</title>
		<link>http://www.chris-mohan.com/2009/02/kicking-off-the-mcitp-enterprise-study-or-msce-2008/</link>
		<comments>http://www.chris-mohan.com/2009/02/kicking-off-the-mcitp-enterprise-study-or-msce-2008/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 09:16:49 +0000</pubDate>
		<dc:creator>Chris Mohan</dc:creator>
				<category><![CDATA[Exams]]></category>
		<category><![CDATA[ISA/TMG]]></category>
		<category><![CDATA[Labs]]></category>
		<category><![CDATA[Study]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[Windows 2008]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=282</guid>
		<description><![CDATA[(or MCSE 2008 as the rest of us call it) For reasons only known to myself, I&#8217;ve stupidly decided to kick off the final two MCITP: Enterprise exams starting with 70-649. Ah, nothing like making bets, attempting to get a bit of competition going, that you can get certified before the rest of the team. [...]]]></description>
			<content:encoded><![CDATA[<h5>(or MCSE 2008 as the rest of us call it)</h5>
<p>For reasons only known to myself, I&#8217;ve stupidly decided to kick off the final two MCITP: Enterprise exams starting with 70-649.</p>
<p>Ah, nothing like making bets, attempting to get a bit of competition going, that you can get certified before the rest of the team.</p>
<p>In front <strong><em>the Boss</em></strong>. (He&#8217;s a hockey playing, beer drinking, Northern ninja for randomly appearing like that!)</p>
<p>Pure Muppet magic on my part! Meep.</p>
<p>Hum ho.</p>
<p>Why the Enterprise rather than the long winded 70-647 update exam first? After skimming the objectives, it looks less work and studying for 749 will help out with 647 at a guess.</p>
<p>Check List:</p>
<p>Study guide:                                         Ms Press Self paced 70-647 Training kit</p>
<p>Hands on:                                              Build a virtual lab on Windows 2008 and use the Ms Virtual Labs</p>
<p>Pick a date to get this done by:    Monday 23rd of March 2009</p>
<p>Better get on with it then.</p>
<p>So, kick off by designing and build and small self contained Windows 2008 domain. This is all built on a physical machine, running Windows 2008 Server x64 with 8GB of RAM, lots of hard disk space and a couple of NICs. Hyper-V is installed.</p>
<p>I&#8217;ve added three additional networks in the Virtual Network Manger: Domain_Internal, DMZ and Hyper-V_External. Hyper-V_External is connected to the router for direct Internet access.</p>
<p>I&#8217;ve build, installed the Integration tools and patched (32updates and 159mb later) one VM, then cloned it (done by copying it to a new location, starting it up and running <a href="http://technet.microsoft.com/en-us/sysinternals/bb897418.aspx">newsid</a>) to speed things up and save download bandwidth. I should have used <a href="http://technet.microsoft.com/en-us/library/cc766320.aspx">Windows Deployment Services (WDS)</a>, but I get around to that later.</p>
<p>The master network plan is below</p>
<p style="text-align: center;"><img class="aligncenter" src="http://www.chris-mohan.com/wp-content/uploads/2009/02/021609-0916-kickingofft1.png" alt="" /></p>
<p>This isn&#8217;t information leakage and I haven&#8217;t forgotten to add IPv6 addresses in, just a basic network diagram!</p>
<p>So once everything has finished installing, on with setting it up.</p>
<p>Now to start going through the notes and playing!</p>
<p><a title="MSCE 2008 Notes part 1" href="http://www.chris-mohan.com/?page_id=292" target="_blank">Notes Part 1</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2009/02/kicking-off-the-mcitp-enterprise-study-or-msce-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing OCS with ISA Server</title>
		<link>http://www.chris-mohan.com/2009/02/securing-ocs-with-isa-server/</link>
		<comments>http://www.chris-mohan.com/2009/02/securing-ocs-with-isa-server/#comments</comments>
		<pubDate>Sat, 14 Feb 2009 10:19:53 +0000</pubDate>
		<dc:creator>Chris Mohan</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=273</guid>
		<description><![CDATA[The folks over at the Technet magazine have publish this little gem on OCS and ISA depolyment Worth a read if you have OCS and need the outside world to connect up to it http://technet.microsoft.com/en-us/magazine/dd440949.aspx]]></description>
			<content:encoded><![CDATA[<p>The folks over at the Technet magazine have publish this little gem on OCS and ISA depolyment</p>
<p>Worth a read if you have OCS and need the outside world to connect up to it</p>
<p><a title="External OCS " href="http://technet.microsoft.com/en-us/magazine/dd440949.aspx" target="_blank">http://technet.microsoft.com/en-us/magazine/dd440949.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2009/02/securing-ocs-with-isa-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fixing a “Bad Request (Invalid Hostname)” &#8211; 400 Error through ISA Server</title>
		<link>http://www.chris-mohan.com/2009/02/fixing-a-%e2%80%9cbad-request-invalid-hostname%e2%80%9d-400-error-on-isa-server/</link>
		<comments>http://www.chris-mohan.com/2009/02/fixing-a-%e2%80%9cbad-request-invalid-hostname%e2%80%9d-400-error-on-isa-server/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 08:14:50 +0000</pubDate>
		<dc:creator>Chris Mohan</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=230</guid>
		<description><![CDATA[We were splitting two web sites to two new servers from the existing one. The sites all worked and resolved internally, so created a new web publishing rules on the ISA for the relocated sites and their host header names. When attempting to access the web site number two the web page displayed: Bad Request [...]]]></description>
			<content:encoded><![CDATA[<p>We were splitting two web sites to two new servers from the existing one. The sites all worked and resolved internally, so created a new web publishing rules on the ISA for the relocated sites and their host header names.</p>
<p>When attempting to access the web site number two the web page displayed:</p>
<p style="text-align: center;"><span style="font-family: Courier New;">Bad Request (Invalid Hostname) &#8211; 400 Error<br />
</span></p>
<p>The web sites still worked internally and the ISA could resolve the server host headers and browse the sites. The rule looked good, pointed to the right location had the right ports open.</p>
<p>Turned on logging and watched for access to the site. No hits. Muck around checking event logs, restarting the firewall services and tweaking the rule. No joy.</p>
<p>Got a pencil and paper out and went through my deployment notes, ticking off each step. Got the web listener for site two and immediately found the problem. I had done a copy and paste of the rule and web listener and hadn&#8217;t changed the IP address of the second web listener to it new address. It was still using the first listener IP.</p>
<p>Added the correct IP address and everything worked as expected.</p>
<p><a title="Meep" href="http://en.wikipedia.org/wiki/Beaker_(Muppet)" target="_blank">Meep</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2009/02/fixing-a-%e2%80%9cbad-request-invalid-hostname%e2%80%9d-400-error-on-isa-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>995 The I/O operation has been aborted because of either a thread exit or an application request</title>
		<link>http://www.chris-mohan.com/2009/02/995-the-io-operation-has-been-aborted-because-of-either-a-thread-exit-or-an-application-request/</link>
		<comments>http://www.chris-mohan.com/2009/02/995-the-io-operation-has-been-aborted-because-of-either-a-thread-exit-or-an-application-request/#comments</comments>
		<pubDate>Sun, 08 Feb 2009 11:53:05 +0000</pubDate>
		<dc:creator>Chris Mohan</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=219</guid>
		<description><![CDATA[Like any normal day in the office, at some point I&#8217;ll get blamed for something not working. More specifically, one of the security systems I manage gets blamed, but I cop the flack for it. Moaning at an inanimate firewall doesn&#8217;t elicit the sheer pleasure of ranting a human being, or me, it appears. Anyway, [...]]]></description>
			<content:encoded><![CDATA[<p>Like any normal day in the office, at some point I&#8217;ll get blamed for something not working.</p>
<p>More specifically, one of the security systems I manage gets blamed, but I cop the flack for it. Moaning at an inanimate firewall doesn&#8217;t elicit the sheer pleasure of ranting a human being, or me, it appears.</p>
<p>Anyway, over the weekend a financial web site had stopped working and they wanted it to work. It was throwing up authentication errors in a Java Applet screen they never seen before. The Web company&#8217;s helpdesk said nothing had changed, so it had to be our problem, or my problem, as normal. Since nothing changed on the network, client machines or firewall rule sets (gotta love change management) and I had a screen shot of the error with times of the problems, I called up the ISA logs, and filtered on the url of the site.</p>
<p>The screen shots filled me with apprehension, as the web site had a big ugly Java error and the pages were <a href="http://en.wikipedia.org/wiki/JHTML">.jhtml</a> and it was all running over SSL. After a chat with the staff member, he said the site looked like it had an update.</p>
<p>I&#8217;ve had problems before with Java programmers doing dubious things over http and the ISA correctly dropping the traffic, so wasn&#8217;t looking forward to getting in to a fight with a big financial web company over coding.</p>
<p>The ISA filter displayed a whole heap of these errors when connecting to the site:</p>
<p><strong>Status: </strong>995 The I/O operation has been aborted because of either a thread exit or an application request</p>
<p>Now this doesn&#8217;t tell you much, so after a quick bit of browsing the web I found a reply from Jim Harrison to someone with similar issues</p>
<p><span style="font-family:Courier New; font-size:10pt">&#8220;This is expected even for normal termination of SSL Tunnel traffic.<br />
</span></p>
<p><span style="font-family:Courier New; font-size:10pt">ISA can&#8217;t follow the HTTP conversation within the SSL session and so the session closure is always a surprise.<br />
</span></p>
<pre><code>It does not indicate an error in ISA."
</code></pre>
<p>I trust Jim&#8217;s advice implicitly, and was sure it was the lovely web company&#8217;s fault, but his reply didn&#8217;t help nail what was wrong and SSL won&#8217;t let me analyse the traffic.</p>
<p>Help came from an unexpected source when the staffer mention he could access the web site at home, after taking a very long time to load to first time.</p>
<p>Did anything else happen while you accessed the site, like some piece of software update? I enquired.</p>
<p>It appears that his machine downloaded the latest version of Java first. Hmm, to the test lab machines!</p>
<p>I fired up a test machine, broke company standard build policy, ripped out the current package version of Java and installed the latest and greatest straight from the web site. This promptly broke the machine. I grabbed the next test machine and attempted to update Java. That broke it too. The third machine, a totally non-standard machine, installed Java without issues and could &#8220;magically&#8221; accessed the site. No need to touch the ISA rules.</p>
<p>Grinning like a <a href="http://en.wikipedia.org/wiki/Cheshire_Cat">Cheshire cat</a> I promptly handed over the mess of updating everyones Java client to the packaging team with a couple of notes on how it had destroyed two perfectly good machines for no apparent reason.</p>
<p><strong>Take away:</strong> if you see status message 995 being logged on ISA, a web app stops working and the site is Java based, then check the Java client and ask what version you should be using to access the site first.</p>
<p>Put money on it that the third party will say &#8220;Install at minimum version X&#8221;, which won&#8217;t be the version you&#8217;re running.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2009/02/995-the-io-operation-has-been-aborted-because-of-either-a-thread-exit-or-an-application-request/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>ISA or TMG on a Virtual server</title>
		<link>http://www.chris-mohan.com/2008/09/isa-or-tmg-on-a-virtual-server/</link>
		<comments>http://www.chris-mohan.com/2008/09/isa-or-tmg-on-a-virtual-server/#comments</comments>
		<pubDate>Sun, 14 Sep 2008 07:36:49 +0000</pubDate>
		<dc:creator>Chris Mohan</dc:creator>
				<category><![CDATA[ISA/TMG]]></category>

		<guid isPermaLink="false">http://www.chris-mohan.com/?p=133</guid>
		<description><![CDATA[Was browsering through Jeffa&#8217;s blog when I found his NAP link posted to another Ms web site call edge.technet.com I had a bit of a browse and found this stand out piece on putting ISA or TMG on a Virtual host and how to secure it. Jim Harrison is a very active Ms guy in [...]]]></description>
			<content:encoded><![CDATA[<p>Was browsering through <a href="http://blogs.technet.com/jeffa36/" target="_blank">Jeffa&#8217;s blog</a> when I found his NAP link posted to another Ms web site call edge.technet.com I had a bit of a browse and found this <a title="ISA goes virtual " href="http://edge.technet.com/Media/Virtualize-your-ISA-or-Forefront-TMG-servers/" target="_blank">stand out piece on putting ISA or TMG on a Virtual host</a> and how to secure it.</p>
<p>Jim Harrison is a very active Ms guy in the ISA world and it&#8217;s well worth watch his walk through of what to do. Enoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.chris-mohan.com/2008/09/isa-or-tmg-on-a-virtual-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

