Applications that reply on the RPC service are blocked in Windows Vista SP1 or in Windows Server 2008 when you block Windows Firewall incoming connections and enable remote management
On a computer that is running Windows Vista Service Pack 1 (SP1) or Windows Server 2008, consider the following scenario:
You set the state of Windows Firewall incoming connections to Block all connections. This puts Windows Firewall in Shields-Up mode.
You enable the Windows Firewall Remote Management rule for Windows Firewall incoming rules.
In this scenario, applications that reply on the Remote Procedure Call service are blocked.
For example, the Forefront Server Security Management Console (FSSMC) agent is blocked from the Remote Procedure Call service and cannot enforce the Windows Firewall policy on the endpoint. Additionally, you may receive an error message that resembles the following:
0x800706D9 - "There are no more endpoints available from the endpoint mapper"
This problem occurs because the Internet Protocol Security (IPsec) Policy Agent (PolicyAgent) service unloads the remote management DLL files and unregisters the remote Remote Procedure Call interface when Windows Firewall is in Shields-Up mode. Therefore, when an application implements the Remote Procedure Call client, the application is blocked.
A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing the problem described in this article. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.
If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.
Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site:
Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.
Prerequisites
No prerequisites are required.
Restart requirement
You must restart the computer after you apply this hotfix.
Hotfix replacement information
This hotfix does not replace any other hotfixes.
File information
The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
Windows Vista and Windows Server 2008 file information notes
The files that apply to a specific product, milestone (RTM, SPn) can be identified by examining the file version numbers that are shown in the following table:
Collapse this tableExpand this table
Version
Product
Milestone
Service branch
6.0.600 0 . 20 xxx
Windows
RTM
LDR
6.0.600 1 . 22 xxx
Windows Vista SP1 and Windows Server 2008 SP1
SP1
LDR
Service Pack 1 (SP1) is integrated into Windows Server 2008. Therefore, RTM milestone files apply only to Windows Vista. RTM milestone files have a 6.0.0000.xxxxxx version number.
The MANIFEST files (.manifest) and MUM files (.mum) installed for each environment are
listed separately
. MUM and MANIFEST files, and the associated security catalog (.cat) files, are important to maintaining the state of the updated component. The security catalog files (attributes not listed) are signed with a Microsoft digital signature.
For all supported x86-based versions of Windows Server 2008 and Windows Vista
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
Fwremotesvr.dll
6.0.6000.21065
28,672
10-Jun-2009
11:58
x86
Ipsecsvc.dll
6.0.6000.21065
361,984
10-Jun-2009
11:59
x86
Ipsecsvc.mof
Not Applicable
1,278
01-Apr-2009
16:07
Not Applicable
Polstore.dll
6.0.6000.21065
272,896
10-Jun-2009
12:05
x86
Polstore.mof
Not Applicable
1,275
01-Apr-2009
16:07
Not Applicable
Winipsec.dll
6.0.6000.21065
61,440
10-Jun-2009
12:06
x86
Winipsec.mof
Not Applicable
1,270
01-Apr-2009
16:07
Not Applicable
Fwremotesvr.dll
6.0.6001.22447
28,672
10-Jun-2009
11:54
x86
Ipsecsvc.dll
6.0.6001.22447
363,008
10-Jun-2009
11:55
x86
Ipsecsvc.mof
Not Applicable
1,278
01-Apr-2009
18:59
Not Applicable
Polstore.dll
6.0.6001.22447
272,896
10-Jun-2009
11:59
x86
Polstore.mof
Not Applicable
1,275
01-Apr-2009
18:59
Not Applicable
Winipsec.dll
6.0.6001.22447
61,440
10-Jun-2009
11:59
x86
Winipsec.mof
Not Applicable
1,270
01-Apr-2009
18:59
Not Applicable
Fwremotesvr.dll
6.0.6002.22150
28,672
10-Jun-2009
11:43
x86
Ipsecsvc.dll
6.0.6002.22150
364,032
10-Jun-2009
11:43
x86
Ipsecsvc.mof
Not Applicable
1,278
03-Apr-2009
20:58
Not Applicable
Polstore.dll
6.0.6002.22150
272,896
10-Jun-2009
11:45
x86
Polstore.mof
Not Applicable
1,275
03-Apr-2009
20:58
Not Applicable
Winipsec.dll
6.0.6002.22150
61,440
10-Jun-2009
11:46
x86
Winipsec.mof
Not Applicable
1,270
03-Apr-2009
20:58
Not Applicable
Netio.sys
6.0.6000.21065
214,104
10-Jun-2009
12:36
x86
Bfe.dll
6.0.6000.21065
317,440
10-Jun-2009
11:57
x86
Fwpkclnt.sys
6.0.6000.21065
85,504
10-Jun-2009
09:52
x86
Fwpuclnt.dll
6.0.6000.21065
543,232
10-Jun-2009
11:58
x86
Ikeext.dll
6.0.6000.21065
416,768
10-Jun-2009
11:58
x86
Wfp.mof
Not Applicable
816
01-Apr-2009
16:13
Not Applicable
Wfp.tmf
Not Applicable
115,173
10-Jun-2009
09:53
Not Applicable
Netiomig.dll
6.0.6000.21065
49,152
10-Jun-2009
12:04
x86
Netiougc.exe
6.0.6000.21065
22,016
10-Jun-2009
09:53
x86
Tcpip.sys
6.0.6000.21065
805,888
10-Jun-2009
09:54
x86
Tcpipcfg.dll
6.0.6000.21065
167,424
10-Jun-2009
12:05
x86
For all supported x64-based versions of Windows Server 2008 and Windows Vista
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
Fwremotesvr.dll
6.0.6000.21065
49,664
10-Jun-2009
12:14
x64
Ipsecsvc.dll
6.0.6000.21065
523,264
10-Jun-2009
12:16
x64
Ipsecsvc.mof
Not Applicable
1,278
01-Apr-2009
16:07
Not Applicable
Polstore.dll
6.0.6000.21065
379,904
10-Jun-2009
12:22
x64
Polstore.mof
Not Applicable
1,275
01-Apr-2009
16:07
Not Applicable
Winipsec.dll
6.0.6000.21065
100,352
10-Jun-2009
12:23
x64
Winipsec.mof
Not Applicable
1,270
01-Apr-2009
16:07
Not Applicable
Fwremotesvr.dll
6.0.6001.22447
50,176
10-Jun-2009
12:10
x64
Ipsecsvc.dll
6.0.6001.22447
532,992
10-Jun-2009
12:10
x64
Ipsecsvc.mof
Not Applicable
1,278
01-Apr-2009
16:07
Not Applicable
Polstore.dll
6.0.6001.22447
380,928
10-Jun-2009
12:13
x64
Polstore.mof
Not Applicable
1,275
01-Apr-2009
16:07
Not Applicable
Winipsec.dll
6.0.6001.22447
100,864
10-Jun-2009
12:14
x64
Winipsec.mof
Not Applicable
1,270
01-Apr-2009
16:07
Not Applicable
Fwremotesvr.dll
6.0.6002.22150
50,176
10-Jun-2009
11:53
x64
Ipsecsvc.dll
6.0.6002.22150
533,504
10-Jun-2009
11:54
x64
Ipsecsvc.mof
Not Applicable
1,278
03-Apr-2009
20:46
Not Applicable
Polstore.dll
6.0.6002.22150
380,928
10-Jun-2009
11:56
x64
Polstore.mof
Not Applicable
1,275
03-Apr-2009
20:46
Not Applicable
Winipsec.dll
6.0.6002.22150
100,864
10-Jun-2009
11:56
x64
Winipsec.mof
Not Applicable
1,270
03-Apr-2009
20:46
Not Applicable
Netio.sys
6.0.6000.21065
321,112
10-Jun-2009
12:55
x64
Bfe.dll
6.0.6000.21065
439,808
10-Jun-2009
12:12
x64
Fwpkclnt.sys
6.0.6000.21065
147,456
10-Jun-2009
10:23
x64
Fwpuclnt.dll
6.0.6000.21065
712,192
10-Jun-2009
12:14
x64
Ikeext.dll
6.0.6000.21065
419,328
10-Jun-2009
12:15
x64
Wfp.mof
Not Applicable
816
01-Apr-2009
16:13
Not Applicable
Wfp.tmf
Not Applicable
115,073
10-Jun-2009
10:23
Not Applicable
Netiomig.dll
6.0.6000.21065
59,904
10-Jun-2009
12:20
x64
Netiougc.exe
6.0.6000.21065
25,600
10-Jun-2009
10:23
x64
Tcpip.sys
6.0.6000.21065
1,190,912
10-Jun-2009
10:25
x64
Tcpipcfg.dll
6.0.6000.21065
232,960
10-Jun-2009
12:23
x64
Fwremotesvr.dll
6.0.6000.21065
28,672
10-Jun-2009
11:58
x86
Ipsecsvc.mof
Not Applicable
1,278
01-Apr-2009
16:07
Not Applicable
Polstore.dll
6.0.6000.21065
272,896
10-Jun-2009
12:05
x86
Polstore.mof
Not Applicable
1,275
01-Apr-2009
16:07
Not Applicable
Winipsec.dll
6.0.6000.21065
61,440
10-Jun-2009
12:06
x86
Winipsec.mof
Not Applicable
1,270
01-Apr-2009
16:07
Not Applicable
Fwremotesvr.dll
6.0.6001.22447
28,672
10-Jun-2009
11:54
x86
Ipsecsvc.mof
Not Applicable
1,278
01-Apr-2009
18:59
Not Applicable
Polstore.dll
6.0.6001.22447
272,896
10-Jun-2009
11:59
x86
Polstore.mof
Not Applicable
1,275
01-Apr-2009
18:59
Not Applicable
Winipsec.dll
6.0.6001.22447
61,440
10-Jun-2009
11:59
x86
Winipsec.mof
Not Applicable
1,270
01-Apr-2009
18:59
Not Applicable
Fwremotesvr.dll
6.0.6002.22150
28,672
10-Jun-2009
11:43
x86
Ipsecsvc.mof
Not Applicable
1,278
03-Apr-2009
20:58
Not Applicable
Polstore.dll
6.0.6002.22150
272,896
10-Jun-2009
11:45
x86
Polstore.mof
Not Applicable
1,275
03-Apr-2009
20:58
Not Applicable
Winipsec.dll
6.0.6002.22150
61,440
10-Jun-2009
11:46
x86
Winipsec.mof
Not Applicable
1,270
03-Apr-2009
20:58
Not Applicable
Fwpuclnt.dll
6.0.6000.21065
543,232
10-Jun-2009
11:58
x86
Wfp.mof
Not Applicable
816
01-Apr-2009
16:13
Not Applicable
Netiomig.dll
6.0.6000.21065
49,152
10-Jun-2009
12:04
x86
Netiougc.exe
6.0.6000.21065
22,016
10-Jun-2009
09:53
x86
Tcpipcfg.dll
6.0.6000.21065
167,424
10-Jun-2009
12:05
x86
For all supported IA-64-based versions of Windows Server 2008