Applies ToMicrosoft Forefront Threat Management Gateway 2010 Service Pack 2 Forefront Threat Management Gateway 2010 Standard Forefront Threat Management Gateway 2010 Enterprise

Symptoms

Consider the following scenario:

  • You enable HTTPS inspection in the Web Access Policy on a server that is running Microsoft Forefront Threat Management Gateway (TMG) 2010.

  • You have clients that access Secure Sockets Layer (SSL) websites through Forefront TMG when a proxy server is not defined.

  • You installed a third-party web filter that calls the WriteClient API.

In this scenario, the Firewall service (Wspsrv.exe) in Forefront TMG may stop responding to all traffic until the Firewall service or the server is restarted.

Cause

This problem occurs because the call to the WriteClient API from a third-party web filter may cause a deadlock situation that blocks all worker threads in the Firewall service.

Resolution

To resolve this problem, install the hotfix package that is described in the following Microsoft Knowledge Base article:

2689195 Rollup 2 for Forefront Threat Management Gateway (TMG) 2010 Service Pack 2

Workaround

To work around this problem, use one of the following methods:

  • Disable the third-party web filter.

  • Disable HTTPS inspection.

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

More Information

For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:

824684 Description of the standard terminology that is used to describe Microsoft software updates

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.