Sheridan Posted May 10, 2011 Posted May 10, 2011 I'm trying to get my TMG 2010 server to update its definitions (for NIS) through our Smoothwall proxy. I've set a web chaining rule to point the TMG at the Smootwall for Microsoft Update sites and set the Smoothwall server to allow unauthenticated access to all of the MS update sites. When I try and update the NIS definitions on the TMG, I can see entries in the Smoothwall log allowing access to the following sites: download.windowsupdate.com update.microsoft.com:443 But on the TMG server I always get the error: An error occurred during an attempt to check for, download, or install definition updates on the server SERVER. The failure is due to error: 0x80244021 The web chaining is obviously working but I can't find what that error code means anywhere?
AMLinington Posted May 10, 2011 Posted May 10, 2011 Try adding the following domains to the 'Do not require authentication for these domains' list and ensure that 'Unauthenticated IP's' are allowed to use the proxy (filtered): windowsupdate.microsoft.com update.microsoft.com c.microsoft.com download.windowsupdate.com genuine.microsoft.com It's probably an NTLM incompatibility thing. Microsoft updates are like that :-7
Sheridan Posted May 10, 2011 Author Posted May 10, 2011 (edited) Thats bascially what I've already got, I even tried allowing *.microsoft.com for unauthenticated users! I have a rule that allows the same sites for unauthenticated users. I can't see anything being blocked by the smoothwall, but it doesn't show blocked request for unauthenticated users does it? Every time I run Windows update on the TMG I see this in the Smoothwall log: http://download.windowsupdate.com/v9/windowsupdate/redi 0 Warning OK (200) exception Exception site match 15:22:28 http://download.windowsupdate.com/v9/microsoftupdate/re 0 Warning OK (200) exception Exception site match 15:22:28 http://download.windowsupdate.com/v9/windowsupdate/redi 0 Warning OK (200) exception Exception site match 15:22:28 http://www.update.microsoft.com/v9/windowsupdate/selfup 0 Warning OK (200) exception Exception site match 15:22:29 http://download.windowsupdate.com/v9/microsoftupdate/re 0 Warning OK (200) exception Exception site match 15:22:29 https://www.update.microsoft.com:443 0 Warning OK (200) exception Exception site match The exception match is because the update sites are all in a policy for unauthenticated users to have access to them. So its Windows Update and also the NIS updates that fail with the same error code. Edited May 10, 2011 by Sheridan
AMLinington Posted May 11, 2011 Posted May 11, 2011 Another place to check is your file download rules - it might be worth trying disabling the entire file download policy and see if the same error occurs again as it might be one of the settings there.
rob_f Posted May 11, 2011 Posted May 11, 2011 If it's listed as "Exception" then file download rules aren't being applied to that domain. The ultimate test is to put the TMG server's address in Guardian > Web Proxy "Exception IP Addresses" and set TMG to use port 801 on the Smoothwall... this is the most extreme form of whitelist/bypass and should help you eliminate your policy configuration.
Sheridan Posted May 12, 2011 Author Posted May 12, 2011 I've managed to get this working by setting the TMG box to update from our WSUS server. Ironically our WSUS server gets its updates using the Smoothwall as a proxy (even more ironically the Smoothwall box utimately goes out through the TMG!) I'll have a crack at the exception IP address and see if that makes a difference.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now