Symptoms
Consider the following scenario:
-
You enable HTTPS inspection in the Web Access Policy on a server that is running Microsoft Forefront Threat Management Gateway (TMG) 2010.
-
You have clients that access Secure Sockets Layer (SSL) websites through Forefront TMG when a proxy server is not defined.
-
You installed a third-party web filter that calls the WriteClient API.
In this scenario, the Firewall service (Wspsrv.exe) in Forefront TMG may stop responding to all traffic until the Firewall service or the server is restarted.
Cause
This problem occurs because the call to the WriteClient API from a third-party web filter may cause a deadlock situation that blocks all worker threads in the Firewall service.
Resolution
To resolve this problem, install the hotfix package that is described in the following Microsoft Knowledge Base article:
2689195 Rollup 2 for Forefront Threat Management Gateway (TMG) 2010 Service Pack 2
Workaround
To work around this problem, use one of the following methods:
-
Disable the third-party web filter.
-
Disable HTTPS inspection.
Status
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.
More Information
For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
824684 Description of the standard terminology that is used to describe Microsoft software updates