| Follow me on:

PDF Creator    Send article as PDF to   

Microsoft UAG – Invalid External Port bug

November 2nd, 2011

Last week I have installed a Microsoft UAG array. I installed Microsoft ForeFront Unified Access Gateway 2010 including Service Pack 1. When using an array configuration you have to deploy Microsoft’s Network Load Balancing (NLB) for redundancy and load balancing purposes. I configured NLB with multicast and IGMP support. I had configured some HTTPS trunks and some HTTP trunks for http-to-https redirection.

Everything was working perfectly and I decided to install the update KB2585140 (ForeFront UAG SP1 Update 1). The main reason for installation was the introduction of SharePoint 2010 with Office Web Apps and Lync web services publishing.

The installation process was easy and completed without any errors. I noticed that after installing the update I couldn’t activate any configuration changes. Everything I hit Activate I receive the following error message:

uag-error-update1

The Activation works again by deleting all HTTP trunks and only use HTTPS trunks. The customer started a support call with Microsoft and Microsoft acknowledges this behavior when installing the update on an array configuration. At first Microsoft advised to “break” the array and use a stand-alone server deployment. If that isn’t an option we should uninstall the update. We are told that the current configuration will get to the configuration state prior to the installation.

This morning the customer received another e-mail from Microsoft stating at more and more calls were logged with the same issues. The issues now has the highest priority for the Microsoft UAG developers. Microsoft couldn’t tell when the issue will be fixed, but I guess very soon.

So when using a Microsoft UAG array configuration DON’T install Microsoft UAG SP1 Update-1.

René Jorissen works as Solution Specialist for 4IP in the Netherlands. Network Infrastructures are the primary focus. René works with equipment of multiple vendors, like Cisco, HP Networking, Juniper Networks, RSA, PaloAlto Networks, Microsoft and many more. René is CCNA (Routing & Switching, Security), CCNP , Cisco ASA Specialist and CEFFS certified. You can follow René on Twitter and LinkedIn.
René Jorissen
View all posts by René Jorissen
Company website

Related Articles

4 Responses to “Microsoft UAG – Invalid External Port bug”

  1. Nick Says:

    Any update from MS on this issue, we have it also.. How do you uninstall the update, is it possible?


  2. René Jorissen Says:

    The customer received an “unofficial” update. This fixed the problem. I guess the best option is to contact support.


  3. Pavel Aleman Says:

    Hello,
    I have this issue, I’ve installed the roll up 1 but still have the problem. I’ve deleted all the trunk and disable Direct Access and still it’s impossible to activate the UAG cluster. Any idea or update could be great for us.

    Thanks so much


  4. René Jorissen Says:

    Dear Pavel,

    I had to delete all the HTTP trunks to get the UAG going. I would suggest to create a support call at Microsoft. My customer did so and he received an update to fix the problem.

    René


Leave a Reply

  • my Tweetz

    • @robmaaseu @aerohive has good features, especially the ppsk is very nice. #byod and mobile users need some more attention in the future 3 hrs ago
    • @robmaaseu @aerohive I do like it, but I miss some functionalities, like auth. fall through, bandwith control per ssid and some more 3 hrs ago
    • Just built another @AeroHive environment with different ssid's, PPSK groups and captive portal designs 4 hrs ago
    • @Aerohive sent me a mail to view last weeks UltraLight Branch Webinar, but I get a "404 Not Found"........ 12 hrs ago
    • @mramsmeets they are for MDM. ClearPass is for secure access to the wifi environment, especially for guest access and #BYOD 16 hrs ago
    • More updates...

    Powered by Twitter Tools