Forefront TMG Service Pack 1 (SP1) can be installed on servers running Forefront Unified Access Gateway (UAG), as follows:
- Forefront TMG SP1 can be obtained from the Microsoft Download Center. For installation
instructions, see Installing Forefront TMG SP1.
- In a Forefront UAG array, Forefront TMG Service Pack 1 should
be installed on each array member. Install SP1 on the array manager
server first, and then on other array members. The build number for
Forefront TMG Service Pack 1 is 7.0.8107.200. To verify that SP1 is
installed on a specific server, in the Forefront TMG Management
console, click Help and select About Forefront Threat
Management Gateway. The build number appears after version.
- It is recommended to stop Forefront UAG services before
applying Forefront TMG SP1. This ensures that no Forefront TMG
files are in use when applying the service pack.
- Read more about Forefront TMG SP1 features in What’s new in Forefront TMG 2010 Service Pack 1.
- Forefront TMG is installed on Forefront UAG servers
automatically during Forefront UAG setup, and acts as a firewall to
protect the Forefront UAG server. For more information about
running Forefront TMG with Forefront UAG, see Supported
Forefront TMG configurations.
Known issues
- For an overview of known issues, read the Forefront TMG SP1 release notes.
- When installing Forefront TMG SP1 on Forefront UAG, the
installation wizard indicates that there are files in use. You can
safely ignore this warning.
- After installing Forefront TMG Service Pack 1, removing a
Forefront UAG array member will not complete as expected and an
error will be issued. As a workaround, do the following:
- Close the Forefront UAG Management console on the array member,
and on the array manager server.
- Click Start, type appwiz.cpl, and press Enter.
Right-click Forefront Threat Management Gateway, and select
Uninstall/Change. In the installation wizard, select
Repair, click Next, and then click
Install.
- After Repair completes, do the following to verify that the
array member has been removed:
- On the server you removed from the array, open the Forefront
TMG Management console. Click the Monitoring node, and then
click the Configuration tab. Under Configuration
Status, verify that the server does not appear as an array
member.
- On the array manager server, open the Forefront TMG Management
console. Click the Monitoring node, and then click the
Configuration tab. Under Configuration Status, verify
that the server you removed from the array does not appear as an
array member.
- On the server you removed from the array, open the Forefront
TMG Management console. Click the Monitoring node, and then
click the Configuration tab. Under Configuration
Status, verify that the server does not appear as an array
member.
- In order to complete removal of the array member, you must
first rejoin it to the array. Do this in the Forefront TMG
Management console running on the server you removed from the
array, as follows:
- In the Forefront TMG Management console, click the
server_name node.
- In the Tasks pane, click Join array.
- On the Join Array Membership page, click Join a
standalone array managed by a designated array member (array
manager).
- On the Array Manager Details page, specify the IP
address or FQDN of the array manager, and then click
Finish.
- In the Forefront TMG Management console, click the
server_name node.
- To verify that the server has rejoined the array, open the
Forefront TMG Management console. Click the Monitoring node, and
open the Configuration tab. Under Configuration Status, check that
the server appears as an array member.
- From the Forefront UAG Management console on the array member
you want to remove, run the Array Management Wizard to remove the
server, as described in Removing an array member
from an array.
- On the array manager, and run the Array Management Wizard. On
the Defining Array Member Computers page, verify that the
server does not appear in the list of array members.
- Close the Forefront UAG Management console on the array member,
and on the array manager server.