ISA Server 2004 Enterprise Edition may stop responding if the firewall does not go into lockdown mode when MSDE logging fails (920893)



The information in this article applies to:

  • Microsoft Internet Security and Acceleration Server 2004, Enterprise Edition

For more information about how to obtain the ISA Server 2004, Standard Edition version of this hotfix, click the following article number to view the article in the Microsoft Knowledge Base:

922946 When ISA Server 2004, Standard Edition receives lots of requests, the program stops responding to requests

SYMPTOMS

If MSDE logging is enabled, and you change the default behavior that puts the firewall into lockdown mode and stops the Microsoft Firewall service when logging fails, Microsoft Internet Security and Acceleration (ISA) Server 2004, Enterprise Edition might start accumulating log records in memory and eventually stop responding in heavy traffic.

CAUSE

By default, when logging fails, ISA Server automatically goes into lockdown mode and stops the Microsoft Firewall Service. This problem occurs if you change this default behavior by using either of the following procedures:
  • You disable "Stop selected services settings" on the Log Failure alert properties. To check this setting in ISA Server Management, follow these steps:
    1. Click the Monitoring node, and then click the Alerts tab.
    2. In the Task pane, click Configure Alert Definitions.
    3. Double-click the Log Failure alert, and verify that the Stop selected services checkbox is selected under the Actions tab.
  • You run the DisableLockdownOnLogFailure.vbs script that is available at the following Microsoft TechNet Web site:

RESOLUTION

Hotfix information

A supported hotfix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Only apply it to systems that are experiencing this specific problem. This hotfix may receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next ISA Server 2004 service pack that contains this hotfix.

To resolve this problem immediately, contact Microsoft Product Support Services to obtain the hotfix. For a complete list of Microsoft Product Support Services telephone numbers and information about support costs, visit the following Microsoft Web site:Note In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.

Prerequisites

ISA Server 2004 Service Pack 2 (SP2) must be installed before you install this hotfix.

Restart requirement

The following services are automatically stopped and then restarted when you install this hotfix:
  • Microsoft Firewall
  • ISA Server Control
  • ISA Server Job Scheduler
  • ISA Server Storage

Hotfix replacement information

This hotfix does not replace any other hotfixes.

File information

The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
File nameFile versionFile sizeDateTimePlatform
Comphp.dll4.0.3443.618167,78413-Jun-200618:43x86
Complp.dll4.0.3443.61863,33613-Jun-200618:43x86
msfpc.dll4.0.3443.618377,19213-Jun-200618:43x86
msfpccom.dll4.0.3443.6185,024,10413-Jun-200618:43x86
ratlib.dll4.0.3443.61840,80813-Jun-200618:43x86
msfpcsnp.dll4.0.3443.6184,656,48813-Jun-200618:43x86
mspadmin.exe4.0.3443.618282,98413-Jun-200618:43x86
msphlpr.dll4.0.3443.618405,35213-Jun-200618:43x86
mspmon.dll4.0.3443.61852,58413-Jun-200618:43x86
mspmsg.dll4.0.3443.618254,31213-Jun-200618:43x86
rpcfltr.dll4.0.3443.618130,92013-Jun-200618:43x86
w3filter.dll4.0.3443.618750,95213-Jun-200618:43x86
wspsrv.exe4.0.3443.6181,065,83213-Jun-200618:43x86
To resolve this problem in ISA Server 2004, Standard Edition, see the following Microsoft Knowledge Base article:

922946 ISA Server 2004 Standard Edition may stop responding if the firewall does not go into lockdown mode when MSDE logging fails

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

Modification Type:MajorLast Reviewed:9/27/2006
Keywords:kbQFE kbfix kbbug kbhotfixserver kbpubtypekc KB920893 kbAudITPRO