<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Richard Hicks&#039; Blog</title>
	<atom:link href="http://tmgblog.richardhicks.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://tmgblog.richardhicks.com</link>
	<description>Microsoft Forefront TMG 2010 and ISA Server 2004/2006 News and Information</description>
	<lastBuildDate>Thu, 23 Feb 2012 23:52:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Load Balancing and Forefront TMG Firewall Clients by Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-2236</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Thu, 23 Feb 2012 23:52:50 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-2236</guid>
		<description><![CDATA[Hi Sherry,

DNS round robin is indeed supported for load balancing Forefront TMG 2010 firewall clients. Information on how to configure DNS round robin can be found here:

http://technet.microsoft.com/en-us/library/cc787484(v=WS.10).aspx

Thanks!]]></description>
		<content:encoded><![CDATA[<p>Hi Sherry,</p>
<p>DNS round robin is indeed supported for load balancing Forefront TMG 2010 firewall clients. Information on how to configure DNS round robin can be found here:</p>
<p><a href="http://technet.microsoft.com/en-us/library/cc787484(v=WS.10)" rel="nofollow">http://technet.microsoft.com/en-us/library/cc787484(v=WS.10)</a>.aspx</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Slipstream Service Pack 2 for Forefront TMG 2010 by Jim Duncan</title>
		<link>http://tmgblog.richardhicks.com/2011/10/23/slipstream-service-pack-2-for-forefront-tmg-2010/#comment-2235</link>
		<dc:creator><![CDATA[Jim Duncan]]></dc:creator>
		<pubDate>Thu, 23 Feb 2012 17:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1752#comment-2235</guid>
		<description><![CDATA[Great info, thanks!

I was having problems slipstreaming SP1 (getting a &quot;Internal error 2203&quot;); it turns out that the MS_FPC_Server.mis file was marked read-only when it was copied from the DVD image. Once I removed the read-only attribute things went perfectly.

Thanks again!]]></description>
		<content:encoded><![CDATA[<p>Great info, thanks!</p>
<p>I was having problems slipstreaming SP1 (getting a &#8220;Internal error 2203&#8243;); it turns out that the MS_FPC_Server.mis file was marked read-only when it was copied from the DVD image. Once I removed the read-only attribute things went perfectly.</p>
<p>Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Load Balancing and Forefront TMG Firewall Clients by Sherry</title>
		<link>http://tmgblog.richardhicks.com/2010/07/09/load-balancing-and-forefront-tmg-firewall-clients/#comment-2234</link>
		<dc:creator><![CDATA[Sherry]]></dc:creator>
		<pubDate>Thu, 23 Feb 2012 01:23:50 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1035#comment-2234</guid>
		<description><![CDATA[Thanks richard and all the commentators for valuable information.

I have two TMG boxes (enterprise FF) in a Single Array - we use firewall client and it resolves to ONE member at a time - 

How can I setup DNS Round Robin within this scenario ? 
Would DNS Round Robin cause connectivity issues (as you say about the firewall client control chanel thing) ?

Will be grateful if you could provide a step by step to create a dns round robin for my two TMG boxes in a Single Array and Firewall Client in action on the client side.

TMGSNR = 192.168.1.1
TMGJNR = 192.168.1.2

Thanks ever so much !]]></description>
		<content:encoded><![CDATA[<p>Thanks richard and all the commentators for valuable information.</p>
<p>I have two TMG boxes (enterprise FF) in a Single Array &#8211; we use firewall client and it resolves to ONE member at a time &#8211; </p>
<p>How can I setup DNS Round Robin within this scenario ?<br />
Would DNS Round Robin cause connectivity issues (as you say about the firewall client control chanel thing) ?</p>
<p>Will be grateful if you could provide a step by step to create a dns round robin for my two TMG boxes in a Single Array and Firewall Client in action on the client side.</p>
<p>TMGSNR = 192.168.1.1<br />
TMGJNR = 192.168.1.2</p>
<p>Thanks ever so much !</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WPAD Considerations for Kerberos Authentication with NLB VIP on Forefront TMG 2010 by Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2012/02/13/wpad-considerations-for-kerberos-authentication-with-nlb-vip-on-forefront-tmg-2010/#comment-2225</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Sat, 18 Feb 2012 03:07:40 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1984#comment-2225</guid>
		<description><![CDATA[Yes, it is a statically updated file. You could probably update it using some type of file replication I would guess...]]></description>
		<content:encoded><![CDATA[<p>Yes, it is a statically updated file. You could probably update it using some type of file replication I would guess&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Running Windows Update on a TMG Firewall Fails with Result Code 80072EE2 by Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2010/08/07/running-windows-update-on-a-tmg-firewall-fails-with-result-code-80072ee2/#comment-2224</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Sat, 18 Feb 2012 03:05:25 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1077#comment-2224</guid>
		<description><![CDATA[Have you confirmed that name resolution is working correctly and that you in fact have outbound network connectivity? Also, you can find more details in the windowsupdate.log file located in the Windows directory.]]></description>
		<content:encoded><![CDATA[<p>Have you confirmed that name resolution is working correctly and that you in fact have outbound network connectivity? Also, you can find more details in the windowsupdate.log file located in the Windows directory.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Running Windows Update on a TMG Firewall Fails with Result Code 80072EE2 by xyyz</title>
		<link>http://tmgblog.richardhicks.com/2010/08/07/running-windows-update-on-a-tmg-firewall-fails-with-result-code-80072ee2/#comment-2223</link>
		<dc:creator><![CDATA[xyyz]]></dc:creator>
		<pubDate>Sat, 18 Feb 2012 01:53:02 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1077#comment-2223</guid>
		<description><![CDATA[sadly, this hasn&#039;t worked for me.  anyone have any more ideas?]]></description>
		<content:encoded><![CDATA[<p>sadly, this hasn&#8217;t worked for me.  anyone have any more ideas?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WPAD Considerations for Kerberos Authentication with NLB VIP on Forefront TMG 2010 by mikehowells</title>
		<link>http://tmgblog.richardhicks.com/2012/02/13/wpad-considerations-for-kerberos-authentication-with-nlb-vip-on-forefront-tmg-2010/#comment-2222</link>
		<dc:creator><![CDATA[mikehowells]]></dc:creator>
		<pubDate>Sat, 18 Feb 2012 01:12:39 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1984#comment-2222</guid>
		<description><![CDATA[Does the login script deploy a manually configured PAC file? If so, how is it kept updated as changes are made to the ISA/TMG array?]]></description>
		<content:encoded><![CDATA[<p>Does the login script deploy a manually configured PAC file? If so, how is it kept updated as changes are made to the ISA/TMG array?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WPAD Considerations for Kerberos Authentication with NLB VIP on Forefront TMG 2010 by Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2012/02/13/wpad-considerations-for-kerberos-authentication-with-nlb-vip-on-forefront-tmg-2010/#comment-2221</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Sat, 18 Feb 2012 00:47:33 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1984#comment-2221</guid>
		<description><![CDATA[I wouldn&#039;t say &quot;most&quot; clients, but I&#039;ve worked with quite a few customers to enable group policy to configure their web proxy client settings. Using GPOs does workaround the WPAD issue we&#039;re discussing here, but as you correctly observed, this is a potential sticking point for mobile devices that need to connect to the Internet outside of the office. In cases like this I&#039;ve actually seen organizations deploy a PAC file on the local file system which is configured to use a direct connection if the proxy server is unavailable. The PAC file is distributed via logon script or any other file replication mechanism.]]></description>
		<content:encoded><![CDATA[<p>I wouldn&#8217;t say &#8220;most&#8221; clients, but I&#8217;ve worked with quite a few customers to enable group policy to configure their web proxy client settings. Using GPOs does workaround the WPAD issue we&#8217;re discussing here, but as you correctly observed, this is a potential sticking point for mobile devices that need to connect to the Internet outside of the office. In cases like this I&#8217;ve actually seen organizations deploy a PAC file on the local file system which is configured to use a direct connection if the proxy server is unavailable. The PAC file is distributed via logon script or any other file replication mechanism.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WPAD Considerations for Kerberos Authentication with NLB VIP on Forefront TMG 2010 by mikehowells</title>
		<link>http://tmgblog.richardhicks.com/2012/02/13/wpad-considerations-for-kerberos-authentication-with-nlb-vip-on-forefront-tmg-2010/#comment-2220</link>
		<dc:creator><![CDATA[mikehowells]]></dc:creator>
		<pubDate>Fri, 17 Feb 2012 20:48:05 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1984#comment-2220</guid>
		<description><![CDATA[In your experience, do you typically see most clients using GPO&#039;s to distribute the proxy name to web browsers?

Since this would not use WPAD this would then allow them to utilize Kerberos (I&#039;m assuming that they would just run that script to change the MakeProxies behavior to return FQDN&#039;s instead of IP&#039;s).

My next question is, if you indeed do see clients using GPO&#039;s to point to the proxy server, how do you handle it when a laptop user leaves the office? Won&#039;t the web browser continue to try to hit the proxy server as served-up by the GPO if the web browser is launched outside of the office?]]></description>
		<content:encoded><![CDATA[<p>In your experience, do you typically see most clients using GPO&#8217;s to distribute the proxy name to web browsers?</p>
<p>Since this would not use WPAD this would then allow them to utilize Kerberos (I&#8217;m assuming that they would just run that script to change the MakeProxies behavior to return FQDN&#8217;s instead of IP&#8217;s).</p>
<p>My next question is, if you indeed do see clients using GPO&#8217;s to point to the proxy server, how do you handle it when a laptop user leaves the office? Won&#8217;t the web browser continue to try to hit the proxy server as served-up by the GPO if the web browser is launched outside of the office?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WPAD Considerations for Kerberos Authentication with NLB VIP on Forefront TMG 2010 by Richard Hicks</title>
		<link>http://tmgblog.richardhicks.com/2012/02/13/wpad-considerations-for-kerberos-authentication-with-nlb-vip-on-forefront-tmg-2010/#comment-2219</link>
		<dc:creator><![CDATA[Richard Hicks]]></dc:creator>
		<pubDate>Fri, 17 Feb 2012 17:49:54 +0000</pubDate>
		<guid isPermaLink="false">http://tmgblog.richardhicks.com/?p=1984#comment-2219</guid>
		<description><![CDATA[Yes, this script works with Forefront TMG 2010 in addition to ISA 2006. There is no requirement to configure SPNs for array members, as they are already registered in the Kerberos database. The only time you need to configure SPNs is when you are using a name that is not the hostname of an array member (for example, the array DNS name). If you want to use WPAD *and* have all requests delivered to the VIP, you will have to use a custom script file.]]></description>
		<content:encoded><![CDATA[<p>Yes, this script works with Forefront TMG 2010 in addition to ISA 2006. There is no requirement to configure SPNs for array members, as they are already registered in the Kerberos database. The only time you need to configure SPNs is when you are using a name that is not the hostname of an array member (for example, the array DNS name). If you want to use WPAD *and* have all requests delivered to the VIP, you will have to use a custom script file.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

