Sign in with Microsoft
Sign in or create an account.
Select a different account.
You have multiple accounts
Choose the account you want to sign in with.


Consider the following scenario:

  • You enable HTTPS inspection in the Web Access Policy on a server that is running Microsoft Forefront Threat Management Gateway (TMG) 2010.

  • You have clients that access Secure Sockets Layer (SSL) websites through Forefront TMG when a proxy server is not defined.

  • You installed a third-party web filter that calls the WriteClient API.

In this scenario, the Firewall service (Wspsrv.exe) in Forefront TMG may stop responding to all traffic until the Firewall service or the server is restarted.


This problem occurs because the call to the WriteClient API from a third-party web filter may cause a deadlock situation that blocks all worker threads in the Firewall service.


To resolve this problem, install the hotfix package that is described in the following Microsoft Knowledge Base article:

2689195 Rollup 2 for Forefront Threat Management Gateway (TMG) 2010 Service Pack 2


To work around this problem, use one of the following methods:

  • Disable the third-party web filter.

  • Disable HTTPS inspection.


Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

More Information

For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:

824684 Description of the standard terminology that is used to describe Microsoft software updates

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.

Was this information helpful?

What affected your experience?

Thank you for your feedback!