<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Load Balancing and Forefront TMG Firewall Clients</title>
	<atom:link href="http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/feed/" rel="self" type="application/rss+xml" />
	<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/</link>
	<description>Microsoft Forefront TMG 2010 and ISA Server 2004/2006 News and Information</description>
	<lastBuildDate>Thu, 09 Feb 2012 00:57:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-1493</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Mon, 23 May 2011 19:21:47 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-1493</guid>
		<description><![CDATA[Shouldn&#039;t be a problem for Web Proxy clients since they don&#039;t make use of a discrete control channel like the Firewall Client does.]]></description>
		<content:encoded><![CDATA[<p>Shouldn&#8217;t be a problem for Web Proxy clients since they don&#8217;t make use of a discrete control channel like the Firewall Client does.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mikehowells</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-1492</link>
		<dc:creator><![CDATA[mikehowells]]></dc:creator>
		<pubDate>Mon, 23 May 2011 14:47:08 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-1492</guid>
		<description><![CDATA[I&#039;m starting to notice a lot of problems when end-users are hitting websites that use AJAX heavily such as Yahoo Mail. Sometimes it will work and other times it will not work. In other words, it is intermittent, which is the worst kind of errors to troubleshoot.

During a live monitoring event via ISA Server I saw that the user was bouncing between proxy array members. Would it make a difference if the user was a web proxy client as opposed to a firewall client? In other words, we know that bouncing between array members will break a firewall client&#039;s communication but how about a web proxy client?]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m starting to notice a lot of problems when end-users are hitting websites that use AJAX heavily such as Yahoo Mail. Sometimes it will work and other times it will not work. In other words, it is intermittent, which is the worst kind of errors to troubleshoot.</p>
<p>During a live monitoring event via ISA Server I saw that the user was bouncing between proxy array members. Would it make a difference if the user was a web proxy client as opposed to a firewall client? In other words, we know that bouncing between array members will break a firewall client&#8217;s communication but how about a web proxy client?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-1459</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Wed, 11 May 2011 23:19:58 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-1459</guid>
		<description><![CDATA[It certainly does. Again, the issue is that the Firewall Client establishes a control channel to a specific array member. If the data channel subsequently initiates to another member for any reason, the connection will break. If your environment is reasonably stable, it is possible that you won&#039;t encounter issues. It is still an unsupported configuration, however.]]></description>
		<content:encoded><![CDATA[<p>It certainly does. Again, the issue is that the Firewall Client establishes a control channel to a specific array member. If the data channel subsequently initiates to another member for any reason, the connection will break. If your environment is reasonably stable, it is possible that you won&#8217;t encounter issues. It is still an unsupported configuration, however.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mikehowells</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-1458</link>
		<dc:creator><![CDATA[mikehowells]]></dc:creator>
		<pubDate>Wed, 11 May 2011 17:22:09 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-1458</guid>
		<description><![CDATA[Does this also apply to an ISA Server 2004 Enterprise Edition array? The reason I ask is because we have a 4-node ISA Server 2004 Enterprise array deployed and we are NOT using DNS round robin for any of our internal clients.

Which begs the question, what has changed in behavior from ISA 2004 moving forward to later version of ISA 2006 and TMG 2010?]]></description>
		<content:encoded><![CDATA[<p>Does this also apply to an ISA Server 2004 Enterprise Edition array? The reason I ask is because we have a 4-node ISA Server 2004 Enterprise array deployed and we are NOT using DNS round robin for any of our internal clients.</p>
<p>Which begs the question, what has changed in behavior from ISA 2004 moving forward to later version of ISA 2006 and TMG 2010?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-1427</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Sat, 23 Apr 2011 00:28:38 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-1427</guid>
		<description><![CDATA[Most often it is simply erratic client behavior and intermittent connectivity issues. It &lt;em&gt;can&lt;/em&gt; work without issues if everything goes perfectly, but since the Firewall Client control channel is established with a single array member, if the connection moves to another array member for any reason the connection will break.]]></description>
		<content:encoded><![CDATA[<p>Most often it is simply erratic client behavior and intermittent connectivity issues. It <em>can</em> work without issues if everything goes perfectly, but since the Firewall Client control channel is established with a single array member, if the connection moves to another array member for any reason the connection will break.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mikehowells</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-1426</link>
		<dc:creator><![CDATA[mikehowells]]></dc:creator>
		<pubDate>Fri, 22 Apr 2011 20:47:49 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-1426</guid>
		<description><![CDATA[What are the symptom(s) that you see when you attempt to hit a load balanced CSS or EMS array (via Microsoft NLB) with the Firewall Client hitting the VIP?]]></description>
		<content:encoded><![CDATA[<p>What are the symptom(s) that you see when you attempt to hit a load balanced CSS or EMS array (via Microsoft NLB) with the Firewall Client hitting the VIP?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-886</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Fri, 17 Sep 2010 00:14:50 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-886</guid>
		<description><![CDATA[Yes, it is a design limitation that can&#039;t be addressed with a hotfix or service pack.  It would likely involve a significant redesign of the Firewall Client control channel mechanism, and potentially the firewall core itself.]]></description>
		<content:encoded><![CDATA[<p>Yes, it is a design limitation that can&#8217;t be addressed with a hotfix or service pack.  It would likely involve a significant redesign of the Firewall Client control channel mechanism, and potentially the firewall core itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RuudBoek</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-881</link>
		<dc:creator><![CDATA[RuudBoek]]></dc:creator>
		<pubDate>Thu, 16 Sep 2010 07:50:09 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-881</guid>
		<description><![CDATA[Is that by design or will that be solved in a future servicepack or hotfix update?]]></description>
		<content:encoded><![CDATA[<p>Is that by design or will that be solved in a future servicepack or hotfix update?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-877</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Wed, 15 Sep 2010 21:56:43 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-877</guid>
		<description><![CDATA[That&#039;s correct.  The only supported method of load balancing for ISA/TMG Firewall clients is DNS round robin.]]></description>
		<content:encoded><![CDATA[<p>That&#8217;s correct.  The only supported method of load balancing for ISA/TMG Firewall clients is DNS round robin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RuudBoek</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-876</link>
		<dc:creator><![CDATA[RuudBoek]]></dc:creator>
		<pubDate>Wed, 15 Sep 2010 15:18:32 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-876</guid>
		<description><![CDATA[If the firewall clients will communicate with the dedicated ip of the array member, will they not lose the HA then, since they won&#039;t be using the NLB virtual IP?]]></description>
		<content:encoded><![CDATA[<p>If the firewall clients will communicate with the dedicated ip of the array member, will they not lose the HA then, since they won&#8217;t be using the NLB virtual IP?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

