Article ID: 813865 - Last Review: June 14, 2007 - Revision: 2.12 FIX: Multiple Registered Web Filters in Active Directory Are Handled Incorrectly
SYMPTOMSAfter you install ISA Server Web filters such as Urlscan or
Link Translation, the ISA Server control service may not start, or the Web
filter may not work correctly and may not appear in the ISA Server Microsoft
Management Console (MMC). This problem only occurs if all the following
conditions are met:
CAUSEThis is a result of an Active Directory replication issue
that occurs when ISA Server Web filters are installed on separate computers in
the domain. In this issue, duplicate entries (that is, "mangled nodes") for the
same Web filter may exist in the ISA server array policy, and ISA Server cannot
handle the mangled nodes correctly. For more information about how to detect
the mangled nodes, see the "More Information" section. WORKAROUNDTo work around this issue, run Active Directory replication
after you install a Web filter on the first computer in the ISA Server array.
Initiate Active Directory replication from the domain controller where that ISA
Server computer was logged on, and then verify that Active Directory
replication was completed. When you do this, you make sure that all domain
controllers have the latest information. You do not have to run Active
Directory replication after the other Web filter installations in the ISA
Server array are completed because Web filter data is global for all arrays.
For more information about how to run this task, see the "References" section
or contact Microsoft Support. RESOLUTION A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing this specific problem. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix. If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix. Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site: http://support.microsoft.com/contactus/?ws=support
(http://support.microsoft.com/contactus/?ws=support)
Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language. The English version of this fix has the file
attributes (or later) that are listed in the following table. The dates and
times for these files are listed in coordinated universal time (UTC). When you
view the file information, it is converted to local time. To find the
difference between UTC and local time, use the Time Zone tab
in the Date and Time tool in Control Panel.
Date Time Version Size File name ---------------------------------------------------------- 26-June-2003 09:07 3.0.1200.270 212,240 Msfpc.dll 26-June-2003 09:08 3.0.1200.270 1,822,480 Msfpccom.dll PrerequisitesISA Server 2000 Service Pack 1 (SP1) is required to install this hotfix. For additional information about how to obtain the ISA Server Service Pack 1, click the following article number to view the article in the Microsoft Knowledge Base:313139
(http://support.microsoft.com/kb/313139/EN-US/
)
How to Obtain the Latest Internet Security and Acceleration Server 2000 Service Pack
Hotfix Replacement InformationThis hotfix does not replace any other hotfixes.Note This hotfix does not remove the mangled nodes from Active Directory. However, with the hotfix installed, ISA Server can handle the mangled nodes correctly. Removing the HotfixYou may not be able to remove the hotfix if the Active Directory storage for the Web filter contains mangled nodes because ISA Server cannot handle the mangled nodes correctly during the removal process. However, ISA Server removes the mangled nodes from Active Directory when you back up and restore your ISA Server configuration. After the backup and restore operations are complete, you can remove the hotfix.To remove the hotfix:
Note If you want to remove mangled nodes from Active Directory manually, contact Microsoft Product Support Services (PSS) for information and assistance. MORE INFORMATIONBecause of the Active Directory replication issue, you may
notice multiple Web filter registration entries for the same Web filter. These
multiple Web filter registration entries appear as duplicated (that is,
"mangled") nodes. For example, you may see the following: CN={87F18571-C71D-4a2f-9111-9E0927A00B51}
msFPCISAPIFilter
CN={87F18571-C71D-4a2f-9111-9E0927A00B51},CN=ISAPI-Filters,CN=Extensions,CN={EE37A70F-E9DE-4674-83C4-D602BBF20E3B},CN=Arrays,CN=Fpc,CN=System,DC=DBVWINEU
CN={87F18571-C71D-4a2f-9111-9E0927A00B51}CNF:12921ebc-b0a5-43cf-9e7f-86266db524f5
msFPCISAPIFilter
CN={87F18571-C71D-4a2f-9111-9E0927A00B51}CNF:12921ebc-b0a5-43cf-9e7f-86266db524f5,CN=ISAPI-Filters,CN=Extensions,CN={EE37A70F-E9DE-4674-83C4-D602BBF20E3B},CN=Arrays,CN=Fpc,CN=System,DC=DBVWINEU
CN={87F18571-C71D-4a2f-9111-9E0927A00B51}CNF:12fc2695-343c-48f0-9aa6-10704ebb683f
msFPCISAPIFilter
CN={87F18571-C71D-4a2f-9111-9E0927A00B51}CNF:12fc2695-343c-48f0-9aa6-10704ebb683f,CN=ISAPI-Filters,CN=Extensions,CN={EE37A70F-E9DE-4674-83C4-D602BBF20E3B},CN=Arrays,CN=Fpc,CN=System,DC=DBVWINEUDomain NC --CN=System ----CN=Fpc ------CN=Arrays --------CN=%Current GUID of your ISA Server Array% ----------CN=Extensions ------------CN=ISAPI-Filters ADSI Edit is available in Windows Support Tools. For additional information about how to install Windows 2000 Support Tools, click the following article number to view the article in the Microsoft Knowledge Base: 301423
(http://support.microsoft.com/kb/301423/EN-US/
)
HOW TO: Install the Windows 2000 Support Tools to a Windows 2000 Server-Based Computer
Back up and Restore the ISA Server ConfigurationTo back up the ISA Server configuration:
REFERENCESYou can use Replmon.exe and Dcdiag.exe to troubleshoot
Active Directory replication issues. For more information, visit the following
Microsoft Web sites: http://www.microsoft.com/windows/windows2000/en/advanced/help/sag_ADcmdTools.htm
(http://www.microsoft.com/windows/windows2000/en/advanced/help/sag_ADcmdTools.htm)
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/default.mspx?mfr=true (http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/default.mspx?mfr=true) http://support.microsoft.com/kb/927229 (http://support.microsoft.com/kb/927229) STATUS Microsoft
has confirmed that this is a problem in the Microsoft products that are listed
at the beginning of this article.
| Article Translations
|
Back to the top
