Jump to content

Recommended Posts

Posted

I have an odd problem with a new Windows 2008 terminal server I have set up.

 

Every request it passes to our TMG 2010 proxy results in an error on the TMG box (details of this error at the end).

 

The terminal server in question is set up as a VM on XenServer and is replacing a 2003 server that was there before (ie. the virtual drive has been formatted and 2008 installed).

 

Anyone got any ideas why this is? I can access internal intranet sites, so those web servers are obviously receiving correctly formed packets, and I can RDP into the machine, etc...

 

It seems to think that the packets are malformed - ie. they don't pass TCP checksum tests on the TMG box.

 

Client Agent Authenticated Client Service Referring Server Destination Host Name Transport HTTP Method Filter Information MIME Type Object Source Cache Information Error Information Source Port Session Type Bidirectional Network Interface Raw IP Header Raw Payload Processing Time Bytes Sent Bytes Received Original Client IP GMT Log Time Authentication Server UAG Array Id UAG Version UAG Module Id UAG Id UAG Severity UAG Type UAG Event Name UAG Session Id UAG Trunk Name UAG Service Name UAG Error Code Internal Service Info Log Field Client Application SHA1 Hash Client Application Trust State Client Application Internal Name Client Application Product Name Client Application Product Version Client Application File Version Client Application Original File Name Client FQDN URL Categorization Reason Forefront TMG Client Version URL Destination Host Name Log Time Client IP Destination IP Destination Port Protocol Action Overridden Rule NIS Scan Result NIS Signature NIS Application Protocol Rule Result Code HTTP Status Code Client Username Source Network Destination Network URL Server Name URL Category Log Record Type Malware Inspection Action Malware Inspection Result Threat Name Threat Level Content Delivery Method Malware Inspection Duration (msec) NAT Address Client Application Path

- TCP - - - 0x0 0x0 49269 0 0 0 10.5.143.192 04/11/2010 16:43:01 - - 0 - 0 - - - - - - 0 1048575 - 04/11/2010 16:43:01 10.5.143.192 10.5.143.240 8080 HTTP Proxy Denied Connection - None - see Result Code 0xc0040031 FWX_E_BAD_TCP_CHECKSUM_DROPPED Internal Local Host - SERVICES - Firewall - 0 -

Posted

Ok, after putting just the result code into Google, and nothing else, I discovered that this issue is a known bug when using TMG in some virtual environments and relates to checksum offloading.

 

To fix it, I disabled the various checksum offloads in the device settings for the network card on the TMG box and all is now well.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...