Article ID: 816460 - Last Review: August 9, 2004 - Revision: 2.4 ISA Server 2000 Service Pack 2 Release NotesOn This PageSUMMARYMicrosoft Internet Security and Acceleration (ISA) Server
2000 Service Pack 2 (SP2) includes all the hotfixes and security bulletins that
are released for ISA Server 2000, including all the hotfixes and security
bulletins that were released as part of ISA Server Service Pack 1 (SP1). ISA
Server 2000 SP2 also includes several additional fixes that are available only
as part of ISA Server SP2. For additional information, click the following article number to view the article in the Microsoft Knowledge Base: 313139
(http://support.microsoft.com/kb/313139/
)
How to obtain the latest Internet Security and Acceleration Server 2000 service pack
MORE INFORMATIONInstalling ISA Server 2000 SP2Microsoft recommends that you install ISA Server SP2 on every ISA Server computer that you deploy in your organization, including on computers that are running only ISA Management or the Message Screener. Before you install ISA Server SP2 on a computer, make sure the computer is disconnected from the Internet. The computer must remain disconnected from the Internet until the ISA Server SP2 installation is completed successfully. After installation, the computer can be safely connected to the Internet. To install ISA Server SP2 on ISA Server 2000 Enterprise Edition, you must be logged on with an account that has domain administrator credentials. To install ISA Server SP2, follow these steps:
Removing ISA Server SP2To remove ISA Server SP2, follow these steps:
Upgrading Firewall Client for ISA Server SP2ISA Server SP2 enhances the stability of the Firewall Client software. Microsoft recommends that Firewall Client computers be updated with the ISA Server SP2 client hotfixes. The Firewall Client Setup program must be run directly from the mspclnt share. If you install the Firewall Client from any other location, the hotfixes that are included in ISA Server SP2 for the Firewall Client will not be installed. (This behavior also occurs if you install Firewall Client by using Add or Remove Programs in Control Panel.) To upgrade Firewall Client with the ISA Server SP2 hotfixes, follow these steps:
Running ISA Server 2000 on Windows Server 2003The following issues apply when you run ISA Server 2000 on Windows Server 2003:
Configuring H.323 application filter settingsFor security reasons, ISA Server SP2 configures the H.323 application filter to stop listening for incoming and outgoing calls. Therefore, ISA Server SP2 minimizes the risk of introducing potential vulnerabilities, such as those described in the following Microsoft Security Bulletin: Microsoft Security Bulletin MS04-001
(http://www.microsoft.com/technet/security/bulletin/MS04-001.mspx)
The updates that are described in the bulletin are included in
ISA Server SP2.To configure the H.323 application filter settings after you install ISA Server SP2, follow these steps:
ISA Server SP2 hotfixesISA Server SP2 includes all ISA Server SP1 hotfixes and also hotfixes that were released after the release of ISA Server SP1. Hotfixes that are included in ISA Server SP1 are listed in ISA Server SP1 Release Notes (http://download.microsoft.com/download/ISAServer2000/readme/SP1/NT5/EN-US/ISA_SP1_Release_Notes.htm) The following table lists the Microsoft Knowledge Base (KB) articles that are associated with some of the hotfixes that are included in ISA Server SP2: 284831
(http://support.microsoft.com/kb/284831/
)
The ISA Server Control service may report Event 14158 after you have installed ISA Server
313318
(http://support.microsoft.com/kb/313318/
)
Cannot relay mail through ISA Server if authentication is required
317122
(http://support.microsoft.com/kb/317122/
)
Web proxy sends TCP reset instead of only closing session
317822
(http://support.microsoft.com/kb/317822/
)
Problems with Web browser if ISA Server 2000 is chained to an upstream Web proxy server
318005
(http://support.microsoft.com/kb/318005/
)
ISA Firewall service cannot start with more than 85 IP addresses on the external network adapter
318319
(http://support.microsoft.com/kb/318319/
)
Access violations occur in the Web proxy service if an impersonation failure occurs
319374
(http://support.microsoft.com/kb/319374/
)
Web Proxy service stops responding
319375
(http://support.microsoft.com/kb/319375/
)
The CERT_CONTEXT structure variable is not available for Web filters in ISA
319376
(http://support.microsoft.com/kb/319376/
)
How to automatically authenticate a user against all trusted domains in ISA
319380
(http://support.microsoft.com/kb/319380/
)
ISA Server 2000 Feature Pack 1 overview
319381
(http://support.microsoft.com/kb/319381/
)
Server-side playlists do not work with ISA Server
321844
(http://support.microsoft.com/kb/321844/
)
ISA Server may cause non-paged pool memory peaks
321846
(http://support.microsoft.com/kb/321846/
)
Incorrect canonicalization in Rules engine
323889
(http://support.microsoft.com/kb/323889/
)
Unchecked buffer in Gopher protocol handler can run code of attacker's choice
324642
(http://support.microsoft.com/kb/324642/
)
Macintosh clients who use MAPI cannot connect to Exchange 2000 with ISA Server
331062
(http://support.microsoft.com/kb/331062/
)
Running ISA Server on Windows Server 2003
331064
(http://support.microsoft.com/kb/331064/
)
ISA reports may span unexpected date range or show incomplete data
331065
(http://support.microsoft.com/kb/331065/
)
MS03-009: A problem in the ISA Server DNS intrusion detection filter may cause denial of service
331066
(http://support.microsoft.com/kb/331066/
)
MS03-012: Flaw in Winsock Proxy service can cause denial of service
331067
(http://support.microsoft.com/kb/331067/
)
ISA reports may contain negative numbers in the 'All Others' row
331068
(http://support.microsoft.com/kb/331068/
)
ISA Firewall causes handle leak in LSASS
331069
(http://support.microsoft.com/kb/331069/
)
Hotfix to permit URL path redirection in Web publishing rules
331070
(http://support.microsoft.com/kb/331070/
)
Authentication does not succeed when the user name contains a space
331073
(http://support.microsoft.com/kb/331073/
)
Description of the standard terminology that is used to describe Microsoft software updates
810493
(http://support.microsoft.com/kb/810493/
)
Update rollup for ISA Server services
810559
(http://support.microsoft.com/kb/810559/
)
Slow responses and failures when you use server publishing UDP protocols
810561
(http://support.microsoft.com/kb/810561/
)
RemoveAllProxyAuthorization not applied to SSL tunneling (CONNECT) requests
813864
(http://support.microsoft.com/kb/813864/
)
Site and content rules do not filter based on file name extensions
813865
(http://support.microsoft.com/kb/813865/
)
Multiple registered Web filters in Active Directory are handled incorrectly
815051
(http://support.microsoft.com/kb/815051/
)
The Firewall Client does not support the ConnectEx and WSARecvMsg APIs
816454
(http://support.microsoft.com/kb/816454/
)
Proxy service logs an Event ID 14146 message after link translation rules are enabled
816456
(http://support.microsoft.com/kb/816456/
)
MS03-028: Flaw in ISA Server error pages could allow cross-site scripting attack
816457
(http://support.microsoft.com/kb/816457/
)
Description of ISA Server changes that are included in Small Business Server 2003 Premium Edition
816458
(http://support.microsoft.com/kb/816458/
)
MS04-001: A vulnerability in an Internet Security and Acceleration Server 2000 H.323 filter could allow remote code execution
816459
(http://support.microsoft.com/kb/816459/
)
ISA Server 2000 hotfix for invalid FTP PORT command
816621
(http://support.microsoft.com/kb/816621/
)
Message Screener causes handle leak in Lsass.exe
816828
(http://support.microsoft.com/kb/816828/
)
"Permission Denied" error message when you use rlogin to log on to a server on the Internet
817829
(http://support.microsoft.com/kb/817829/
)
Passive mode FTP may break with multiple IP addresses on external interface
818136
(http://support.microsoft.com/kb/818136/
)
Web Proxy service may crash when it processes a redirect action
818621
(http://support.microsoft.com/kb/818621/
)
No links to navigate up through directory levels in FTP sites when accessed through Internet Explorer
818821
(http://support.microsoft.com/kb/818821/
)
ISA Firewall service stops responding on DNS resolution
819962
(http://support.microsoft.com/kb/819962/
)
"414 Request-URI Too Large" error message from ISA Server
821098
(http://support.microsoft.com/kb/821098/
)
Content cache issues on downstream ISA Server computer
821724
(http://support.microsoft.com/kb/821724/
)
Basic credentials may be sent over an External HTTP connection when SSL is required
821935
(http://support.microsoft.com/kb/821935/
)
ISA Server Web Proxy service stops responding when the CacheConnectSize registry value is set to 0
822241
(http://support.microsoft.com/kb/822241/
)
ISA Server Web Proxy service maintains a connection after a client session is closed
822970
(http://support.microsoft.com/kb/822970/
)
Cannot read ISA Server performance data by using an SNMP program
823261
(http://support.microsoft.com/kb/823261/
)
Web Proxy Service returns "The User Name Was Not Allowed" error message after the FTP Server returns the "User Logged In" message
823359
(http://support.microsoft.com/kb/823359/
)
ISA Server Web Proxy does not append the domain name suffix to the credentials that are passed to an FTP server
823646
(http://support.microsoft.com/kb/823646/
)
ISA Server forces CERN FTP connections to the Root directory
824246
(http://support.microsoft.com/kb/824246/
)
Response that contains the cache-control: s-maxage=0 header does not expire immediately
828044
(http://support.microsoft.com/kb/828044/
)
ISA Server intermittently stops responding to Web Proxy client requests
829892
(http://support.microsoft.com/kb/829892/
)
You cannot connect to external FTP Sites by using a WRQ reflection FTP client through ISA Server 2000
829893
(http://support.microsoft.com/kb/829893/
)
RSA SecurID cookie expires frequently, and clients are repeatedly prompted to authenticate
830295
(http://support.microsoft.com/kb/830295/
)
SSL bridging request fails with HTTP/1.1 500 (Operation would block. ...)
831140
(http://support.microsoft.com/kb/831140/
)
Web content does not appear, or clients receive an "HTTP 502 Proxy Error" message when they try to access external Web sites with ISA Server 2000
831531
(http://support.microsoft.com/kb/831531/
)
Outbound PPTP connections may disconnect after 60 seconds if the ISA Firewall Service is running
832168
(http://support.microsoft.com/kb/832168/
)
SecurID does not redirect to the requested page after successful logon
833009
(http://support.microsoft.com/kb/833009/
)
ICMP traffic is not blocked during startup period with ISA Server
839019
(http://support.microsoft.com/kb/839019/
)
White spaces in URL are not correctly encoded or decoded when you log on
| Article Translations
|
Back to the top
