??? ????? 2 ?????? ?????? ??????? 2010

?????? ????????? ?????? ?????????
???? ???????: 2288900 - ??? ???????? ???? ????? ????? ??? ???????.
????? ???? | ?? ????

?? ??? ??????

??????

??????? ??????? ??? ???????? ???? ??????? ???? ????? ? Microsoft Forefront ??????? ?????? ??? ????? (UAG) 2010. ??? ????? ??????? ??????? ?????? Forefront (UAG)? ???? ????? ????????? ???????? ?? ??? ???????. ????? ??? ??????? ????????? ??????? ??? ??? ???????:
  • ??????? ??????? ?????????? ???? ??????? ??? ???????
  • ???????? ???? ?? ???? ?? ??? ???????
  • ????? ?????? ??? ??? ???????
  • ????????? ??????? ?????? ??? ???????
  • ???????? ????????

?????

???? ??? ??????? ????? 2 ? Forefront UAG 2010 ??? ?????? ????? ??????? ???????. ????? 2 ? Forefront UAG 2010 ???? ??????? ???????:
  • ????? ?????? ??????:??? ???? ??? ?????? Forefront UAG SSL ??????? ????? (???? ??????? ???? ???????) ??? ???? ??????? Windows Vista ?????? ??????? 64 ?? Windows 7 ???????? 32 ??. ???? ?????? ????? ?????? ??? ???????? ?????? ??? 3 ?????? ??? ???? ?? ?????????.
    ?? ??? ??????????? ??? ??????
    ????Windows XP 32 ?????? ??????? Windows Vista 32 ?????? ??????? Windows Vista 64 ??Windows 7 32 ??Windows 7 64 ?????? ??????? Mac ?? ???? ??????? Linux
    ????? ??? ??????????????????????
    ??????? ??? ??????????????????????????
    ????? ?? ???? ?????????????????????????
    Wiper ????????????????????????
    ???? ??? SSL??????????????????
    ???? ??????? ????? ????????????????????????
    ??? SSL ???????(???? ?????)???????????????
    ??????:?????? ??? ??????? ????? ?? ????? ????????? ?????? ????? ???? ???? ??????? ????????? ?? ?????? ???? ??? Microsoft TechNet ???????:
    ????? ??? ??????? ?????? ????? ??????? Forefront UAG
  • ?????? ??????? ??? ?????? ???????? (VDI):????? forefront UAG ??? ??? ?????? ?????? ??? ??????? ??? ?????? ??????? ?? VDI ?????.
  • Citrix ????? ?????:???? forefront UAG Citrix 4.5 ??? ?????? ??? ?????? ??????? ????? ?? Citrix XenApp 5.0 ???? ????.
  • ??? ????????? ?????? Citrix:forefront UAG ???? ???? ??????? Windows Vista ? Windows 7 ????? ????????? ?? ????? ??????? 64 ?? ?????? ??? ????????? Citrix XenApp ??? ???? ?????? XenApp 32 ??. ???? ??????? ??? 4 ????? ????? ?? ????????.
  • ?????? SSTP ????? ???? ?????? ??? ????????:forefront UAG ???? ?????? ???? ???? ????? ???? ????????? ?????? ????????? ??????? ?????? SSTP.
  • ????? SSL:???? forefront UAG ???? ?????? ???? ?????? ?? handshakes SSL ??? UAG ?????? ??? ????????.
  • ????? ????? ??????:????? forefront UAG ???? ???? ?? ??? ????? ????????? ??? ????? ???? ??????? ??????? ?????? ????? ?????? ???????.
  • ?????? ????? MAC ???? ??????:???? forefront UAG ???? ????? ???? ??? ???? ???? ?? ?????? ???? ??????? ??? ???? ????? MAC ????.
????? ?? ????????? ??? ??????? ??????? ?? ????? 2 Forefront UAG 2010? ???? ?????? "?? ?? ?????? ?? Forefront UAG" ?? ???? ??? Microsoft ???????:
????? ??? ????? ???????? ???? ????? ??? UAG Forefront

??????? ????

????? ?????????

????? ????? ?????? ??????? ?? "???? ??????? ? Microsoft":

?? ??? ??????????? ??? ??????
?????
?? ?????? ???? ??????? ????? ??????? ?????? Forefront (UAG) 2 ????.  

?????? ??? ???? ?? ????????? ??? ????? ????? ????? ??? Microsoft? ???? ??? ??? ??????? ?????? ???? ??????? ?? ????? ????? Microsoft:
119591????? ?????? ??? ????? ??? Microsoft ?? ??????? ??? ????????
Microsoft ???? ??? ????? ????? ?? ?????????. ??????? Microsoft ???? ?????? ??? ??????? ???? ???? ?????? ??? ??????? ???? ?? ??? ?????. ??? ????? ????? ??? ?????? ????? ?????? ???? ????? ??? ??? ????? ??? ??????? ??? ???? ??? ??? ?????.

????????? ???????

??? ??????? ???????? ????? ??????? ??? ????? ???????? ?? ??????? ???????? ???? ???? ?????? ??????? UAG 2010 ???????:
  • 2010 UAG (RTM)
  • ????? 2010 UAG 1
  • ???? ??????? ?????? ????????? 1 ????? 2010 UAG 1
????? ?? ????????? ??? ??????? UAG 1? ???? ??? ??? ??????? ?????? ???? ??????? ?? ????? ????? Microsoft:
981323??? ????? 1 ?????? ?????? ??????? 2010
????? ?? ????????? ??? ???? ????????? ??????? UAG ??????? ???????? 1 1? ???? ??? ??? ??????? ?????? ???? ??????? ?? ????? ????? Microsoft:
981932??? ????? ????????? ??????? ????????? 1 ???????? ?????? ??? ????? 2010 ??????? 1

??????? ???????

????? ??????? ????? ???? ??????? ???? UAG ??? ?????????
  1. ?? ?????? ??????? 2 ??? ?????? ?????? ?????.
  2. ????? ????? ?????????.
  3. ?? ?????? ??????? UAG.
  4. ???????? ?????? ??????.
  5. ?? ?????? ??????? 2 ??? ??? ?????? ??? ?????? ?????.
  6. ????? ????? ?????????.
  7. ????? ????? ????? ?????? ????????.
????????? ??? ??? ???????? ??? ?? ???? ????? ????? ??????? ??????? 2 ?? ????? ????.

?? ?????? ????? ???????

???????????? ??? ????? ?? ???? ????? ????? ???? ????????? ??? ????? ???? ??????? ???. ??? ?? ???? ?????? ??????? UAG ??? ????? ???? ???????. ?????? ?????? ?? ????? ????? ??????? UAG ???? ????? ?? "??? SSL ???????" ????????? ???????? ??? ?????? UAG.

?????? ????? ?????????????? ????? ???????. ????? ??????? ?????? ????? ?????? ?? ??? ???? ????? ??????? ??? ??????? ????? ???? ????? ?????? ??? ??????? ??? ?????? ?????? ???????.

??????? ??????? ??????? ??????

?? ??? ??? ??????? ?????? ??? ??? ????????? ??????? ???? ?? ??????? ??????.

??????? ????? ???????

?????? ????? ??? ???????? ?????? ???? ????????? ?????????:
  • Log on as a built-in administrator, and then uninstall the update by using the Programs and Features applet in Control Panel.
  • From an elevated command prompt, type the following command, and then press ENTER:
    msiexec.exe /uninstall {31F37A8F-7454-453C-B084-9334E3EBA839} /package {9B0CE58E-C122-4CB4-80C1-514D4162C07C}

??????? ?????

????? ????? ????? ?????????? ?? ??? ??????? ?????? ???? ????? (?? ???? ??????? ??????) ???????? ?? ?????? ??????. ??? ??? ???????? ???????? ?????? ???? ??????? ?? "??????? ???????" (UTC). ????? ???? ???? ??????? ?????? ??? ??????? ??? ??????? ??????. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

?? ??? ??????????? ??? ??????
??? ?????????? ???????? ??????????????????????? ???????
Agent_win_helper.jar??? ???? ???????1,286,01530-Aug-201013: 12??? ???? ???????
Clientconf.xml??? ???? ???????6,67515-Sep-201006:41??? ???? ???????
Configdatacomlayer.dll4.0.1269.200192,40015-Sep-201008: 13x 64
Configdatalayer.dll4.0.1269.2003,871,63215-Sep-201008:06x 64
Configmgrcom.exe4.0.1269.200199,56815-Sep-201008:01x 64
Configmgrcomlayer.dll4.0.1269.2002,246,03215-Sep-201008:15x 64
Configmgrcore.dll4.0.1269.2001,375,63215-Sep-201008:23x 64
Configmgrinfra.dll4.0.1269.2001,599,88815-Sep-201008:12x 64
Configmgrlayer.dll4.0.1269.200215,44015-Sep-201008:05x 64
Configuration.exe4.0.1269.2008,920,97615-Sep-201008:22x 64
Detection.js??? ???? ???????14,59115 ?????? 201007: 20??? ???? ???????
Https_whlfiltappwrap_forpor??? ???? ???????60,96115 ?????? 201007: 19??? ???? ???????
Http_whlfiltappwrap_forport??? ???? ???????59,47515 ?????? 201007: 19??? ???? ???????
Install.js??? ???? ???????11,21815 ?????? 201007: 20??? ???? ???????
Installanddetect.asp??? ???? ???????12,06715 ?????? 201007: 20??? ???? ???????
Internalerror.asp??? ???? ???????8,34415 ?????? 201007: 20??? ???? ???????
Internalerror.inc??? ???? ???????24,40215 ?????? 201007: 20??? ???? ???????
Login.asp??? ???? ???????24,18315 ?????? 201007: 20??? ???? ???????
Logoffmsg.asp??? ???? ???????7,70530 ????? 201013: 11??? ???? ???????
Microsoft.uag.da.messages.d4.0.1269.20033,68015 ?????? 201008: 14x 64
Microsoft.uag.transformer.c4.0.1269.2006,297,48815 ?????? 201008: 02??????? x86
Monitormgrcom.exe4.0.1269.200151,95215 ?????? 201008: 01x 64
Monitormgrcore.dll4.0.1269.200740,24015 ?????? 201008: 23x 64
Monitormgrlayer.dll4.0.1269.200354,19215 ?????? 201008: 12x 64
Policy.xml??? ???? ???????80,24417 ?????? 201012: 16??? ???? ???????
Policydefinitions.xml??? ???? ???????61,51615 ?????? 201007: 15??? ???? ???????
Redirecttoorigurl.asp??? ???? ???????1,42330 ????? 201013: 11??? ???? ???????
Repairinstallation.vbs??? ???? ???????3,04430 ????? 201013: 12??? ???? ???????
Ruleset_forinternalsite.ini??? ???? ???????47,01930 ????? 201013: 11??? ???? ???????
Sessionmgrcom.exe4.0.1269.200233,87215 ?????? 201008: 24x 64
Sessionmgrcomlayer.dll4.0.1269.2001,641,36015 ?????? 201008: 02x 64
Sessionmgrcore.dll4.0.1269.200738,19215 ?????? 201008: 01x 64
Sessionmgrinfra.dll4.0.1269.2001,197,96815 ?????? 201008: 22x 64
Sessionmgrlayer.dll4.0.1269.200200,59215 ?????? 201008: 04x 64
Sfhlprutil.cab??? ???? ???????57,19415 ?????? 201008: 35??? ???? ???????
Shareaccess.exe4.0.1269.200492,94415 ?????? 201008: 12x 64
Sslbox.dll4.0.1269.20058,76815 ?????? 201008: 14x 64
Sslvpntemplates.xml??? ???? ???????28,70430 ????? 201013: 12??? ???? ???????
Sslvpn_https_profiles.xml??? ???? ???????96817 ?????? 201012: 16??? ???? ???????
Uagqec.cab??? ???? ???????64,84215 ?????? 201008: 36??? ???? ???????
Uagqessvc.exe4.0.1269.200207,76015 ?????? 201008: 04x 64
Uagrdpsvc.exe4.0.1269.200144,27215 ?????? 201008: 14x 64
Uninstalluagupdate.cmd??? ???? ???????21215 ?????? 201008: 41??? ???? ???????
Usermgrcom.exe4.0.1269.200119,18415 ?????? 201008: 01x 64
Usermgrcore.dll4.0.1269.200837,00815 ?????? 201008: 01x 64
Whlasynccomm.dll4.0.1269.200107,40815 ?????? 201008: 14x 64
Whlcache.cab??? ???? ???????265,76815 ?????? 201008: 36??? ???? ???????
Whlclientsetup-all.msi??? ???? ???????2,964,99215 ?????? 201008: 22??? ???? ???????
Whlclientsetup-basic.msi??? ???? ???????2,964,99215 ?????? 201008: 01??? ???? ???????
Whlclientsetup-networkconne??? ???? ???????2,965,50415 ?????? 201008: 04??? ???? ???????
Whlclientsetup-networkconne??? ???? ???????2,965,50415 ?????? 201008: 03??? ???? ???????
Whlclientsetup-socketforwar??? ???? ???????2,964,99215 ?????? 201008: 24??? ???? ???????
Whlclntproxy.cab??? ???? ???????242,71315 ?????? 201008: 35??? ???? ???????
Whlcompmgr.cab??? ???? ???????689,48315 ?????? 201008: 35??? ???? ???????
Whlcppinfra.dll4.0.1269.200669,58415 ?????? 201008: 23x 64
Whldetector.cab??? ???? ???????263,76415 ?????? 201008: 36??? ???? ???????
Whlfiltappwrap.dll4.0.1269.200315,28015 ?????? 201014: 02x 64
Whlfiltappwrap_http.xml??? ???? ???????59,47515 ?????? 201013: 19??? ???? ???????
Whlfiltappwrap_https.xml??? ???? ???????60,96115 ?????? 201013: 19??? ???? ???????
Whlfiltauthorization.dll4.0.1269.200311,69615 ?????? 201014: 23x 64
Whlfilter.dll4.0.1269.200589,20015 ?????? 201014: 22x 64
Whlfiltsecureremote.dll4.0.1269.2001,037,20015 ?????? 201014: 22x 64
Whlfiltsecureremote_http.xm??? ???? ???????77,40430 ????? 201013: 11??? ???? ???????
Whlfiltsecureremote_https.x??? ???? ???????80,30817 ?????? 201012: 16??? ???? ???????
Whlfirewallinfra.dll4.0.1269.200444,81615 ?????? 201008: 13x 64
Whlgenlib.dll4.0.1269.200511,37615 ?????? 201008: 04x 64
Whlglobalutilities.dll4.0.1269.200106,38415 ?????? 201008: 05x 64
Whlinstallanddetect.inc??? ???? ???????4,47630 ????? 201013: 11??? ???? ???????
Whlio.cab??? ???? ???????167,27715 ?????? 201008: 35??? ???? ???????
Whlioapi.dll4.0.1269.20076,17615 ?????? 201008: 04x 64
Whliolic.dll4.0.1269.20015,76015 ?????? 201008: 22x 64
Whlios.exe4.0.1269.200137,10415 ?????? 201008: 24x 64
Whllln.cab??? ???? ???????167,09515 ?????? 201008: 36??? ???? ???????
Whlllnconf1.cab??? ???? ???????6,52115 ?????? 201008: 35??? ???? ???????
Whlllnconf2.cab??? ???? ???????6,61015 ?????? 201008: 36??? ???? ???????
Whlllnconf3.cab??? ???? ???????6,59915 ?????? 201008: 35??? ???? ???????
Whltrace.cab??? ???? ???????254,35215 ?????? 201008: 36??? ???? ???????
Whltsgauth.dll4.0.1269.200184,20815 ?????? 201008: 02x 64
Whltsgconf.dll4.0.1269.20087,44015 ?????? 201008: 22x 64
Whlvaw_srv.dll4.0.1269.200138,12815 ?????? 201008: 05x 64
Wioconfig.dll4.0.1269.200496,52815 ?????? 201008: 01x 64



???????? ???? ?? ??????? ???? ??????? ??? ???????

???? ??? ??????? ??? ????? ???????? ??????? ???? ?? ??? ??????? ?????? ?? ????? ????? ??????? ? Microsoft.

??????? ??????


???? ?????

????? ????????? ?????? ??????? ?????? ?????? ?????? ?????? ???????? (VPN) ???????? ??????? ?????? ???? ??????? ?????? (SSTP) ?????? ???. ??? ????? ?? ???? ??? ????? SSTP ??? UAG ????? ????? ????? ?????? ??? ???? VPN ?????? ??? "???? ??????? ????????" ?????.

???????? ??? ???? ?????? ?? http://technet.microsoft.com/en-us/library/ee522953.aspx? ??? ?????? ??????? ???? ?????? ????? ????? ??? (TMG) ?????? ????? ???? ?????? ?????? ??????? ?????? ????? VPN SSTP:

"????? ????? ?????? ???????? ???? ???? ????? TMG Forefront? ?? ??? ????? ?????????? ?????????? ???????? ?????? ??? ????? ??? ????? UAG Forefront ?????? ??? ?????? ?? ??? ?? VPN."

??? ???? ??? ????????? ????? ????? ?????? ?????? ???? ????????? ??? ????? ??? ??????? ?? ????? ????? ???? ?????? ??? ????? UAG. ???? ???? ?? ??????? ?????????? ?? ???????? ???? ????? ?????? ?????? ???????.

?????

???? ??? ???????? ???? ???? ???? ?? ??????? ??????? ??? UAG ???????? ???? ?? ??????? ???? ???? ???? ??? ????? ??? TMG ????? ????? ??????? UAG.

?????

??????? ?????? TMG ??????? ???? ?????? ??????? ??? ????? ??? ?? ???? ?? TechNet ?? depreciated (??? ??? ??????? ??? ????? 2 ????? UAG) ????? ??? ???? ?????? ??????? ??? ????? ?? ???? ???? ????? UAG.

???? ???? ????????? UAG ????? ????? ?????? ??? ?????? ???? ????? ?????? ????? ?????????? VPN SSTP ????? ??????? ????? ?? "???? Active Directory". ??? ?? ?????? ????????? UAG ?????????????? ???????????? ????? ??????? ?? ???? ?????? ????? ????? ????? ????? SSL ?????? ??? ?????? IP VPN ?????? ???? ????? ?? ?????? ?? ????? ??????. ???? ?? ????? ?????? ?? ?????? IP ?????? ???????? ??????? ?????? IP ???? ???? ?????? ????? ????? ?????? "???? Active Directory" ????? ????? ??????? ? VPN SSTP.

??????? 2


???? ?????

??? Microsoft ?????? ???????? ???? ?????? ??????? (VDI) ?? UAG ??? ????? ???? ????.

?????

????? ?????? ???????? UAG ????? ??????? ????? ??? ???????? ??? multi-authorization ?? ????? ?????? ????? ??????? ??? VDI ???? ???? ????.

?????

???? ??? ?????? ????? ??????? ??? ????? ????? ???????? UAG ?????? ??? ????????? "??? ?????? ???????" ?? VDI ?????? ?? ???? ??????. ?? ????? ??????? "???? ??? ??????" ?? VDI ??? ???? ????? ?? ??????? ???????? ? UAG.

??????? 3


???? ?????

???? ???? UAG ????? ??????? SSL (???? ??????? ???? ???????) ??? ????? ?? ????? 64 ?? ?? Windows 7 ???????? 64 ?? ?? ???? ??????? Windows Vista.

?????

???? ?? ??????? ?????? ?? ?????? ?????? UAG ??? ????? 2 ????? UAG.

?????

???? ?????? ????? ??????? ??? ????? ??? ????????? ??????:

???? ??? ????? ??????? ??? ???? ??????? ????? ????? ???? ??????? UAG/??? ??????? ?????? ???. ??? ???? ??????? ????????? Citrix XenApps ? 4.5 Server ????? ????????? ???? ???? ???? ???????? ActiveX ?? ????????. ??? ??? ???????? ????? ?????? ???????? ????? ??? ??? ??? ????? ????? ??? ????? 64 ?? ?? ????? ????? ??????? ???????. ?????? ???? ?????? ??? ??????? ??????? ???? ???? ?????? ??? ???????? ?? ????? 32 ?? ?? ?????? ????? systemss ????? ?? ????? ????? 64 ??.

????????? ???? ?? ??????? ???? ????????? ????? ????? ??????? ?????? "????? ?????" ???? ??????? (SF) ???????? ??? ????? 64 ?? ?? ????? ????? ???? Windows ?????? ??? ??????? ?????. ???? ??????? ???????:
  • ????? "???? ??????? ???? ???????" ????? ??? ????? 64 ?? ?? ???? ??????? Windows Vista ???????? 64 ?? ?? Windows 7? ???? ????? 64 ?? ?? ????? ??????? ??? ????????.
  • ???? ??????? ????? ????? ????? ??? ????? ??? ?????????? ??? UAG ?? ????? 32 ?? ?? Internet Explorer (??? ??????? ?? ?????? ?? WOW64 32).
  • ???? ??????? ????? ????? ???? ??? ???????? ?? ??????? 32-?? (??????? WOW64) ???? ?? ????? ??????? ?? ??????? 64 ?? ??????.
The following are the deployment options for the updated components:
  • Online: The standard method that performs deployment of SF components. On the very first invocation of any UAG portal application that uses SF as the tunneling publishing method, the components are downloaded and installed.
  • Offline: Administrators can also deploy the appropriate Windows Installer application (MSI) on a client by using scripted software distribution or by manual installation. After the installation of UAG Update 2 the files will be available on the UAG server in the following location:
    %UAG installation directory%\von\PortalHomePage\
????? 4


Symptom

You cannot access Citrix XenApps 5.0 that is published with UAG from a client computer that is running a 64-bit version of Windows Vista or Window 7.

Cause

This is the designed behavior of the UAG client components before the release of UAG Update 2.

Resolution

Refer to the ?Resolution? section of Issue 3 for detailed information.

????? 5


Symptom

When you try to create or edit an endpoint policy, the ?McAfee Total Protection? policy appears two times on the list. If you select the second ?McAfee Total Protection? policy, you receive an error message that resembles the following:

source line could not be located

Cause

This issue occurs because the %UAG installation directory%\von\Conf\PolicyDefinitions.xml file contains two entries that have the same title and ID.

Resolution

The double entry issue is resolved by removing the second record from the PolicyDefinitions.xml file.

????? 6

Symptom

When you access a resource that is published by UAG, clients receive an error "An unknown error occurred while processing the certificate" in the browser. Also, the UAG administrator may see in UAG server debug logs thatSEC_I_CONTINUE_NEEDEDis returned during the SSL negotiation step "Handshake Confirm State." Following that step the debug logs will show that the/InternalSite/InternalError.asppage is returned to the client together with error code 37. Error Code 37 is the error message "An unknown error occurred while processing the certificate."

Cause

The existing SSL mechanism does not correctly handli several scenarios when it performs SSL handshake with a back-end server published through UAG. The streaming nature of SSL creates a complicated scenario with a possibility of receiving either insufficient data or reading too much information during the handshake. In this scenario,InitializeSecurityContextreports that you have passed additional data that must be saved for use in the future (presumably after you read more data across the wire).

Resolution

The handshake algorithm is extended to support additional streaming cases and scenarios.


??????? 7

???? ?????

??? ?????? ??? ????? HTTPS ????? ?? ???? UAG? ????? ???????? ????? 37: "??? ??? ??? ????? ????? ?????? ???????." ??? ??? ????? ???? ??? ?????? ?????? ??????? (????? ????? ?????? SSLBOX_BASE) ????? ???? ???????? ??????? ??? ??????? ??? ??? ????? ??????? ?????? ???????:
???: ??? ????? ???? ??????. ????? ?????: 0x90320.

InitializeSecurityContext SEC_INCOMPLETE_CREDENTIALS ?????? ? Schannel ????? ?????? ?????? ????? ??????
?????

?? ????? ???? ????? ??????? ??????? ???????? ??????? ?????? ????? ?????? ????? ????? ?????? SSL. ??? ??? ??????? ???? ??? ????? ??? ?????. ?????? ???? ????????? ?? ???? ???.

?????

???? ????? ?? ???????????? ???????? ??? ???? ?????? ?????? ???????? ?????? ???????? ????? ??????:
  • ???? ????? ??????? ??????? ???? ????? ???? ?????? ??? ???? ?????? ???? ?? ?????. ???? ?????? ???? ????????? ?? ????? ??? ???? UAG ?????? ?????? ??????? ???sec_incomplete_credentials?? ???? ??? ???????. ???? ?? ????? ????? ?????? ??? ?????? ?????? ?????? ????? ??????? ??? ?????.
  • ????? ??????? ??????? ?????? ????? ??????. ????? ??????? ???? ?? ?????? ?? ???? ?????? ?????? ???? ?? ???? ?????? ?????? ???? ?? ???? ????? ???? ???? ??? ????? ???? ?? ?????? ????? ??? ????? ??????? ????? ??????????.

    ??? ????? ????? ???? ???? ??????? ??? ?????? UAG ?????? ???? ??????? UAG ???? ??????.
    1. ?????? ?????? ??????? SSLBox UAG ??????? ??????? ??? ??????? ???????? ???? ??????? ???????:
      1. ?? ?????? ????? MMC ???? ???? ???? ???????.
      2. ???? ??????? ?? ???? ????????/????? ???? ??????.
      3. ??????????? ???????? ?? ???? ????????.
      4. ??? ???? ?????????? ??? ?? ???? ????????.
      5. ?????????????? ????????.
      6. ??? ????? ?????? ?????? ???????? ?? ??????? ????? ????? ??????? ??? certificate.Or ?? ?????? ?????? ??? ??????? ??? ???? ??????.
      7. ?????????????? ???????? ??? ????.
      8. ??????? ????????????.
      9. ?? ?????? ???? ??????? ?? bellow ???? ?? ?? ???? ?????? ?????? ?? ?? ???? ????? ??? CTRL + C.
      10. ?????? ?????? ????? ?? ?????? ??? ??????? ???? ?????? ?? ????? ????? ???????. ??? ???? ?? ???? ?????? ????? ?? ???? ????? ????? ?????? ??? ?????. ?????? ???? ?? ????? ??? ??????? ??????. ?????? ??? ??????? ????????? ????? ????????? ????? ??? ??????. ???? ???? ????? ??????? ????? ?? ???? ???? ?????. ?????? ??? ???? ?? ????????? ??? ????? ??? ???? ???????? ?? ????? ?????????? ???? ??? ??? ??????? ?????? ???? ??????? ?? ????? ????? Microsoft:
        322756????? ??? ???? ???????? ?? ????? ????????? ?? Windows
        a. ??? ????? "???? ???????" (Regedt32.exe).

        b. ????? ???? ??? ?? ???? ??? ??????? ?????? ?? ???????:

        HKEY_LOCAL_MACHINE\SOFTWARE\WhaleCom\e-Gap\Von\UrlFilter\Comm\SSL
        c. ???????????????? ???? ???????? ????? ?? ?? ?????? ???? ??????? ???????:
        ??? ??????:ClientCertHash
        ??? ????????:?????
        ??????: {??? ???? ??????? ?? ?????? 9} [??? ???? ??????:a7 36 4b ca 87 3f ???? 10 d5 4b 0f ca 83 9e 9e 74 c8 3e fa 8b]
        d. ????? "???? ???????".
        e. ????? IISReset ?????? ?????? ????? IIS.
        f. ????? ?? ????? UAG.
????? 8

???? ?????

?? ??? ??????? ??????? ????? ????? ????????? ??????? ???? ????? ??? ?????? ???? UAG ???? ????? ????? ??? ????? 85 ?????? "uagqecsvc" ????? ????? ????? Windows ??? ????? ????? ???? ??? ?????? ?? ???? UAG. Although this a false alarm, this fills up the client event logs making it difficult for administrators or the helpdesk from spotting real events in the client?s Windows Event logs. These messages will always be displayed on the client every minute if that client connects to an IAG server.
Event ID: 85

Source: uagqecsvc

Type: Error

Description: The Microsoft Forefront UAG Quarantine Enforcement Client component cannot initialize the enforcement client callback HRESULT value: 0x8027000E. This issue may occur if security policies do not enable the component.

There may also be another related event in the client event logs.
Event ID: 16

Source: uagqecsvc

Log Name: Application

Description: The Microsoft Forefront UAG Quarantine Enforcement Client component cannot retrieve the status of the Network Access Protection (NAP) Agent service. System error 1115: A system shutdown is in progress. (0x45b). When the Microsoft Forefront UAG Quarantine Enforcement Client component starts, it attempts to query settings of the NAP agent service.

Although this issue is not directly related to UAG or to UAG deployments, it is possible that with some deployments users who have the UAG client components installed on them will access both IAG and UAG servers.

?????

UAG Client Components have a component service "uagqecsvc" with a display name of "Microsoft Forefront UAG Quarantine Enforcement Client" which queries endpoint health status by using NAP and reports the status back to the NAP module on UAG. In some rare cases this issue will be seen in UAG deployments as the service re-tries repeatedly to bind to the UAG server. The bind will run in loop with a minute time-out until it can connect.

Additionally starting with IAG Service Pack 2 Update 3, the UAG Client Components were ported to IAG. Therefore the uagqecsvc service is also installed on client computers that connect to any IAG server that has Service Pack 2 Update 3 client components. Because NAP endpoint detection functionality does not exist in IAG, the client that has the UAG components installed on them will continue to try to connect to the UAG NAP service every minute, in the process generating the previously mentioned log messaged in the Windows Event logs.

?????

In the earlier versions of the Client Components the default time-out for retries to communicate with the UAG NAP detection agent was set to a minute, it is been changed in UAG Update 2 to one hour. For administrators who want to modify this value a way to manually define the time-out on the client is provided.

?????? ?????? ????? ?? ?????? ??? ??????? ???? ?????? ?? ????? ????? ???????. ??? ???? ?? ???? ?????? ????? ?? ???? ????? ????? ?????? ??? ?????. ?????? ???? ?? ????? ??? ??????? ??????. ?????? ??? ??????? ????????? ????? ????????? ????? ??? ??????. ???? ???? ????? ??????? ????? ?? ???? ???? ?????. ?????? ??? ???? ?? ????????? ??? ????? ??? ???? ???????? ?? ????? ?????????? ???? ??? ??? ??????? ?????? ???? ??????? ?? ????? ????? Microsoft:
322756????? ??? ???? ???????? ?? ????? ????????? ?? Windows
Computer users or administrators can manually define on any client computer the time-out in milliseconds. ?????? ????? ???? ??????? ???????:
  1. Start Registry Editor (Regedt32.exe).
  2. Locate and then click the following key in the registry:
    HKEY_LOCAL_MACHINE\SOFTWARE\WhaleCom\Client\QEC
  3. ???????????????? ???? ???????? ????? ?? ?? ?????? ???? ??????? ???????:
    ??? ??????:InitRetryTimeout
    ??? ????????: REG_DWORD
    ????? ???????: ??????? ???????
    ??????: (????? ??????? ????? 360000 ?????????? ??? ??? ?? ???? ??? ??????
    ????? ???? ?? 6000)
  4. ????? "???? ???????".
  5. ?? ?????? ????? ???? ????????? ????? ??.
??????? 9
???? ?????

(????? UAG) ???? UAG ?????? ??? ???? ???? ?????? ????? ??? APAC ????? ?? Windows R2 2008. ??? ?????? ????? trunk ??? UAG? ????? ????? ????? ?????? ??? ????? ????? trunk.

??? ???? ??????? ?????? ?????? ????? ??? ??? ????? ?? MMC ?????? ??????? ???? ???? ??? ?????? ????? trunk ??? UAG.

?????

???? ??? ??????? ???? manipulations ??? ????? ?? ????? ??????. ???? ??? manipulations ??? ????? ??? ??? ??? ????? UAG ??? ??? ??????? ?????? ??? ???? ?? ????? ??????? (????/??????/????).

?????

??? ?? ???? ????????? ???????? ??????? ?? ?????? ??? ????? ?????? ???.

??????? 10


???? ?????

??? ??? ????? "???? ????? ???? ???" ???? ??????? ??????? ??? ????? ????? ???? ????????? ?? ???? ?????. ???????? ??? ???? ??? ???? "??????" ?? ???? ??? ???? ?????? ?????? ??? ????? ????? ?????????.

?????

??? ????? ?????? "???? ????? ???? ??? ???? ???????" ????? ???? ????? ??? ???????? ????? ?. ???? ??????? ??? ???? Windows ???? ????? "???? ????? ???? ??? ???? ???????" ???????? ??? ????? ????? ?????????. ??? ???? ?? ???? ????? ??????? ??? ??? ?????? ???? ?????? ??????? ???? ????? ??? ??????. ?????? ???? ???.

?????

??? ???? ????? ???? ?????? ???? ???? ??? ????? ???????? Wiper ???????? ???? ?? ??????? ??? ???????? ????? ? ?????? ??? ?????? ???????? ???? ?? ???.

??????? 11


???? ?????

??? ?????? ?????? ??? ????? ????? ?????? ?? Exchange Server 2007 Outlook ????? ??? ??? (OWA) ???? ??? ????? ??? UAG? ???? ????? ????? ??????? ?????? ??????? ??? ??????.

??? ?????? ?????? ??? ???? ???? ??????? ?????.

?????

???? ??? ??????? ??? ???? ???? ?????? ? Exchange Server 2007 ?? ???? OWA ?? ??? ????? RuleSet URL"/owa/languageselection.aspx". ?? ???? ??? ?????? RuleSet UAG ?????? ??? ?? ???? ???? ????????? ??? ????? ?? ??????? ???????.

?????

??? ????? ????? ????? ???? ?????? ??????? ??? ??? ?????? ???? ???? ????????? ? OWA 2007 Exchange. ?? ??? ??????? ???? ??????? ??????? "ExchangePub2007_Rule36" ?????? ??? ???? ???? ????????? "/owa/languageselection.aspx".

????? 12


???? ?????

????? ????? ??? ?????????? ?????? ??? ???? UAG ?? ????? ?????? ??? ???? ?? ??????? ???????? ?? ??????? ????? ?? ???? ????? ?????? UAG? ????? ??? "???? ?????" 500 ???????? ???? ???? ??? ?????? ??? ??????.

???????????? UAG ADFS ???????? ????? ????? ????? ??????.

?????

????? ??? ????? UAG ???????? ADFS ????????? ???? ????? ????? ??? ??? ?? ???? ??? ?????? (STS) ????? UAG ????????. ??? ?? ??? ??? ?? redirectes ???????? ????????? UAG ?????? ???????. ????? ????? ?????? ?????? ?????? ??? ???? ????? ????? ?? ???? ??????? ???? ??? ????? re-routing. ?????? ???? ??? ????? ?? ??????.

?????

?? ????? ??? ??????? ?? ??? ???????.

??????? 13

???? ?????

????? ??? ????? ????? ?????? ?????? ??? ActiveDirectory? ?? ???? ??????? ????? ?????? ????? ?????? ??? "??? ????". ???? ???????? UAG? ?? ???? ???? ????? ????? ?????? ?????. ??? ???? ????? ???? ????? ?????? ??? ??? ??????? ?????? ??????? ??? ????? ?????? ??? ???? ??? "0" ??? ??? ?????.

??????MMC UAG ????? ??? ????? ????????? ???? ?????? ??? ?????? "0" ??????. ???????? UAG, "0" ???? ?? ???? ?? ???? ????? ??????. ?????? ????? ?????? ?? ???? ??? ?? ?????.

?????

???? ??? ??????? ???? ?? ???? ????? ?????? ??????? ????? ????? ?????? ?? ???????. ?????? ?? ???? ????? ?????? ??????? ??? ?? ????? ???????? ???????? ????? ????????.

?????

The value in the configuration is now properly stored and updated when the group nesting value is deleted from the GUI Additionally, the value is properly applied to the authentication functions.

??????Microsoft recommends setting the value to be the lowest number that is required for the authorization in UAG. You can set the value to higher than 2 levels of nesting due to the potential delay and the required resources. If higher than 2 levels are required for a deployment, you must test the impact of these changes before the system is deployed in production. In extreme cases, these settings can cause both the UAG server and any DCs that are being used for authentication by UAG to crash because of high resource demands.

Issue 14


???? ?????

When you try to close the Network connector (NC) server configuration window after you enable the NC server, you may receive the following error message:

Wrong Network Connector parameters, invalid segment address

?????

The SSL Network Tunneling service can be used only when the physical network adapters have MAC addresses that begin with "00".

?????

The SSL Network Tunneling service can be used even though the physical network adapters have MAC addresses that begin with "00".

Issue 15


???? ?????

UAG was released with only partial support for Citrix XenApp 5.

When you want to publish Citrix without errors, they were obligated to follow the steps that are provided in the following Microsoft website:
Introduction to how to publish Citrix XenApp 5.x with UAG 2010

?????

This issue occurs because the support for Citrix is broken.

?????

The steps that are provided in the above to properly publish Citrix XenApp 5.0 are now included in this update.

Issue 16


???? ?????

The AV product "Trend Micro OfficeScan Anti-Virus" or "Trend Micro PC-Cillin Anti-Virus" is selected from the GUI. In this case, when you create a policy and then apply the policy to an application, you receive the following error message during the activation:

Source Line could not be located

?????

This issue occurs because the policy syntax validation algorithm misses dependencies that are required by these particular policies.

?????

The dependencies that are required by these policies are added to policy syntax validation algorithm after you install this update.

???????? ????????

  • After you install this update the SSL Network Tunneling network adapter becomes invisible in the Network Connections window. This behavior is by design. To make sure that the network adapter is installed open Device Manager and select ?Show Hidden Devices? entry on the View menu.
  • Sometimes the uninstall update operation may fail with an error message, specifying that the installation file ?FirefrontUAG.msi? cannot be found or with the installation error 1269.
    1. Open Start menu and typeShow hidden files and folders.
    2. In the opened window advanced settings clear theHide protected operation system files (Recommended)option and press?????.
    3. Open an elevated Command Prompt window and typeUninstallUagUpdate.
    4. Wait several minutes for the installation database repair if it is required.
      ??????You might receive a message that informs you of the need for a repair.

  • Citrix XenApp support is only for version 5.0. Later versions are not supported.
  • This release only supports the Personal Desktop scenario of VDI. Pooled desktop scenario is currently not supported.
  • Socket Forwarding is available on Window 7 and Vista 64 bit clients for 32 bit applications (WOW64 applications). It is not available for native 64 bit applications.
  • Publishing OWA for Exchange 2010 Service Pack 1 by UAG requires manual modification of an AppWrap and modifications to the RuleSets. An article about the steps that are required to do this is published on the UAG Product team bloghttp://blogs.technet.com/b/edgeaccessblog/. The steps that are described in the article will be integrated into a future update of UAG.
  • Microsoft Customer Support Services (CSS) cannot provide support to customers if they use beta, non-RTM, or non-generally-available (GA) products such as Internet Explorer 9 Beta. Support for IE9 will be included in a future update after IE9 is officially released.

Known issues with Arrays and Network Load Balancing (NLB)

  • When you try to join two servers to the same array at the same time, the array storage may be corrupted. If this happens, restore the settings from backup.
  • ????? ???? ???? IPv6 ????? ????? IP (VIP) ?? ???? ???? ????? UAG Forefront? ?? ?? ??? ????? ??????? ???????. ??? ??? ???????? ?????? ??? ????? ?? ???? ???? ?? ?????? ????? ???????? ??? ???? ???? ????? UAG Forefront.
  • ?? ?? ????? forefront UAG ?? ??? ???? ???????? ???? ??????? NLB ???? ??????? ??????? (??? ???? ??????? ???? ???? ??????-??? ????). ?? ??? ?????????? ?? ????? Forefront UAG ?????? ???? ?????? ??? ?????? ??? ?????. ????? ??? ???????? ?? ?????? ???????? ???????? ????????? ????? ?????? ??? ????. ????? ???????? ??? ???? ??? ?? ??? ?? ?????? ?? ???????.
  • ??? ??? ???? Microsoft ?????? ???? ?????? ????? 2007 ?????? ?? ??????? ????? ?????? ???? ?????? ???? ??????? ??? ??????. ?????? ????? ???? ??????? ???????:
    • ???? ?? ??? ?? ?? ????? ??? ????? ???? ????? ???? Windows ? NLB 2008 ???? Windows ??? ?? ??? ??????.
    • ??????? ?????? ????? 2007 ?????? ?? ?????? ???? ??????? ??? ????? ??? ????? ??????.
      ???????????? ????? 2007 ?????? ??????? ??? ???:
      • ??? ?? ??? ???? ????? ?? ?????? ?????? ??????? ????????? ?????? 2007 ????? ???????? ??? ????? ?? ?? ????.
      • ??? ?? ??? ???? ????? ?? ?????? ?????? ????? ??????? ????????? 2007 ????? ???????? ?? ????? NLB Windows.
  • ????? ???? ?????? trunk ????? ????? trunk HTTPS ?? ???? ?? ????? ????? ?????? ???????? ??? ?? ???? ?????? ?????? IP trunk ????? ??????? ?????? ??? ??? ??????. ??? ??? ??? ?????? ?? ??????? ???????:
    ????? ??? ????? ????? ??????? 1 ??? ???? ???????? NLB


???????

???? ???????: 2288900 - ????? ??? ??????: 27/?? ??????/1431 - ??????: 1.0
????? ???
  • Microsoft Forefront Unified Access Gateway 2010
????? ??????: 
kbexpertiseinter kbinfo kbsurveynew atdownload kbmt KB2288900 KbMtar
????? ????
???: ??? ????? ??? ?????? ???????? ?????? ????? ???? ????? ?????????? ????? ?? ????????? ?????? ????. ???? ???? ?????????? ???? ?? ???????? ???????? ?????? ????????? ????? ????????? ???????? ????? ???????? ?????? ?? ?????? ??? ?? ???????? ???????? ?? ????? ??????? ?????? ??? ??????? ?????? ??. ?????? ?? ???? ??? ??????? ???????? ????? ?? ???? ????? ?????? ??? ????? ??? ????? ??????? ?? ????? ?? ?????? ??? ??? ??????? ??????? ?? ????? ????? ????? ????? ?????. ?? ????? ???? ?????????? ??????? ??? ????? ?? ??????? ?? ????? ?????? ?? ??? ????? ?? ????? ??????? ?? ???????? ?? ??? ???????. ???? ???? ?????????? ???????? ??? ????? ?????? ??????? ??????
???? ??? ????? ??????? ?????? ??????????2288900

????? ???????

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com