Quantcast
Channel: E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control
Viewing all 312 articles
Browse latest View live

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
I find some workaroud.
All configuration need to do in TMG console.
Error not desapire bot mail frow is working and spam is filtring.
MCSE:S, MCSE:M, MCITP, MCTS, CCNA, CCDA Infrastructure expert

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Hello,

I am having the same problem.

Installed forefront TMG + exchange 2010 edge + FSE on 2008 domain member.
1 Exchange 2007 and 1 exchange 2010 with MB, CAS and HUB roles.

Same logging in eventlog :
E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

I'm able to send, but receiving mail is very unreliable : sometimes e-mails arrive immediatelly, sometimes after a long time, and sometimes not at all ( without anti-spam / anti-virus filters active yet)

Could someone please Help.

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Same here. Didn't find any solution. I was forced to implement TMG 2010 without Exchange Edge and Protection :(((
I don't believe it's a rare issue or hardware specific.

Dawid

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Have some problem, and can`t find solution 3 mount.
MCSE:S, MCSE:M, MCITP, MCTS, CCNA, CCDA Infrastructure expert

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
I think the error is serious problem. I have reproduced the same situation in VMWare :-( using clean install of all servers. I will not switch any production servers to Exchange 2010 and Forefront TMG without clear solution.

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Can't say I notice any malfunction, but the 31506 error continues to fill up logs.

I should probably also mention that I have this error message alternating with eight identical info messages:

---------------------------------------
Log Name:      Application
Source:        MSExchangeTransport
Date:          06.01.2010 21:45:02
Event ID:      16022
Task Category: Configuration
Level:         Information
Keywords:      Classic
User:          N/A
Computer:      xx
Description:
A configuration update for Microsoft.Exchange.Transport.ReceiveConnectorConfiguration has successfully completed.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="MSExchangeTransport" />
    <EventID Qualifiers="16388">16022</EventID>
    <Level>4</Level>
    <Task>16</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2010-01-06T20:45:02.000000000Z" />
    <EventRecordID>125787</EventRecordID>
    <Channel>Application</Channel>
    <Computer>xx</Computer>
    <Security />
  </System>
  <EventData>
    <Data>Microsoft.Exchange.Transport.ReceiveConnectorConfiguration</Data>
  </EventData>
</Event>
---------------------------------------

I guess Exchange actually tries to apply some obscure changes, but is correctly dismissed. Of course, I'm not sure.

I'll be watching this tread, hopefully the TMG team shows up!

-olav

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Hi, I'm having the same problem.

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0

Hi Nick,

please unmark Olav's answer, my proposal was accidental. His solved problem was completely unrelated to Kiwisek's (and mine) problem, which is still an uresolved isuue. Maybe there is somebody who can help.

Thanks,
Dawid


E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
I'm pretty sure also this error isn't as trivial as it seems, but I haven't found a solution yet. Looks like nobody (except us) on the net experiencing this behavior. It's crowding application log and getting really annoying! Kiwisek, just hoping your worries are incorrect.
Maybe somebody from Microsoft could contribute. Please, HELP!

Dawid

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
I am not sure, if you can simply ignore the problem. I am afraid it resets active connections :-(

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Solved my problem, but the 31506 error continues. Will disregard.

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
"And I have found one more probelm. After restart the Microsoft Forefront TMG Control service stays off and I have to start it manual"

Hi Martin,

Try setting the service IsaManagedCtrl ("Microsoft Forefront TMG Managed Control", not to be confused with "Microsoft Forefront TMG Managed Control") to startup type "Automatic (Delayed start)". No other Exchange/TMG services to delayed start. That worked for me so I don't have to start manualy. I even tested setting back to regular automatic, and it fails again.

But the annoying 31506 error keeps logging.
This time I can't find anything missing in the e-mail policy configuration that was meant to be applied to the edge server.
So I guess it means nothing in my case after all, and I have to find other ways to get incoming mail past the edge.

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Hi DawidGK,

no, no solution up to now :-(

And I have found one more probelm. After restart the Microsoft Forefront TMG Control service stays off and I have to start it manual :-(

Best regards

Martin

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Hi Martin,

have you found a reason why is event id 31506 from Microsoft Forefront TMG Control source reappearing in application log every 1-2 minutes? I've got the same error in application log followed with TMG alert/warning E-mail Policy - Configuration Reapplied and it's getting really annoying.

Thanks,
Dawid

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0

Hi Martin,

Yes, I manually started the IsaManagedCtrl serrvice for a while until I finally had the service startup setting "Automatic (delayed start)" working. Or maybe I solved that one after a certificate configuration change. Still no incoming mail and error 31506 keeps repeating while an edge subscription is active.

At some points I probably did not have the correct certificate setup. I've been searching and frankly I'm still not sure what is expected from Exchange/TMG. Right now I'm running like this:
- Edge: The TMG/Exchange edge server has 3rd party EV SSL SAN cert for IIS/Exchange use (covering mail. owa. and autodiscover.).
- Hub: The Exchange hub/cas/mailbox server has a cert with CN computername.domainname.rootdomain from our enterprise CA.

The 3rd party cert is added to the web listenerer of the TMG. Running Get-ExchangeCertificate on each server returns no other certificates. The edge server has SMTP set with Enable-ExchangeCertificate, and the hub has likewise enabled SMTP, IMAP, POP and IIS.
While trying some shots in the dark I deleted the self-issued cert once created by the Exchange Edge installation, but re-creating, or adding a cert from the enterprise CA did not help.

I get errors while trying to see the properties of the two Receive Connectors from the EMC on the edge:

- The operation couldn't be pererformed because object '<EdgeServerName>\External_Mail_Servers' couldn't be found on 'localhost'. It was running the command 'Get-ReceiveConnector -Identity '<EdgeServerName>\External_Mail_Servers''.

- The operation couldn't be pererformed because object '<EdgeServerName>\Internal_Mail_Servers' couldn't be found on 'localhost'. It was running the command 'Get-ReceiveConnector -Identity '<EdgeServerName>\Internal_Mail_Servers''.

Then, from the shell all loos ok as far as I can see:

[PS] C:\Windows\system32>Get-ReceiveConnector -Identity '<EdgeServerName>\External_Mail_Servers'

Identity                   Bindings            Enabled
--------                   --------            -------
Helm\External_Mail_Servers {85.196.xxx.xxx:25} True


[PS] C:\Windows\system32>Get-ReceiveConnector -Identity '<EdgeServerName>\Internal_Mail_Servers'

Identity                   Bindings                            Enabled
--------                   --------                            -------
Helm\Internal_Mail_Servers {192.168.xxx.xxx:25, 85.196.xxx.xxx:25} True


I'm not sure if this has anything to do with the lost mail.
Otherwise it looks like settings keep in sync now.

Logging in TMG filtered by SMPT and LDAP (Edge) and LDAPS (Edge) always return two entries while sending an e-mail to the organization:

- Initiated Connection <EdgeServerName> 29.12.2009 19:26:44
Log type: Firewall service
Status: The operation completed successfully. 
Rule: [System] Allow SMTP traffic to the local host for mail protection and filtering
Source: External (213.158.233.150:57511)
Destination: Local Host (85.196.xxx.xxx:25)
Protocol: SMTP
 Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 213.158.233.150

- Closed Connection <EdgeServerName> 29.12.2009 19:26:49
Log type: Firewall service
Status: A connection was gracefully closed in an orderly shutdown process with a three-way FIN-initiated handshake. 
Rule: [System] Allow SMTP traffic to the local host for mail protection and filtering
Source: External (213.158.233.150:57511)
Destination: Local Host (85.196.xxx.xxx:25)
Protocol: SMTP
 Additional information
Number of bytes sent: 2054 Number of bytes received: 467
Processing time: 5414ms Original Client IP: 213.158.233.150


Later, this one repeat (like error 31506), trying from hub to edge:

- Denied Connection <EdgeServerName> 29.12.2009 19:34:04
Log type: Firewall service
Status: A non-SYN packet was dropped because it was sent by a source that does not have an established connection with the Forefront TMG computer. 
Rule: None - see Result Code
Source: Internal (192.168.xxxx.xxx:11936)
Destination: Local Host (192.168.yyy.yyy:50636)
Protocol: LDAPS(EdgeSync)
 Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 192.168.xxx.xxx


Any ideas?
Thanks.

-olav


E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
Hi Olav,

I had the problem with incoming e-mail too. It was caused by stopped service "Microsoft Forefront TMG Managed Control". Just try to start it and look at "nestat -na -p TCP" there should be an open port 25 on some of the interfaces. Without the IsaManagedCtrl service started there is no SMTP port open.

Best regards

Martin

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0

Hi, I'm having the same problem.
It looks like I can't set up the TMG e-mail policy since it is getting overwritten all the time. We can send e-mail but can't receive. I'm really lost (and embarrassed) after trying for two weeks.

Exchange installation is not exactly our core activity. We have been running our own Exchange servers because mailbox access and other messaging operations have been essential in several of our software products. We also run our company mailboxes from this installation. I decided that we could risk the upgrade for TMG in a low-activity period, without first setting up a lab network. Now I truly regret...

Soon heading for to another solution, I'd like to see if anybody could make anything out of a case like this (please bear with me; I'll try to make it short):

We used to have one Exchange 2007 box and a single ISA2006 at the edge. All was nice. Then the network got replaced by a number of new Windows 2008 servers, and for some reasons we decided to keep it clean Win2008. So the ISA server had to go, replaced by a few separate edge servers while waiting for the Win2008 ready TMG. Later, all servers were upgraded to Win2008 R2, we set up a plain Exchange 2010 box set up with CAS/HUB/mailbox roles, and a plain edge server with Exchange 2010 edge role. Ok so far, but I couldn't make the web/mobile client access work this time.

A few weeks ago the Forefront Trust Management Gateway was RTM, and the TMG's integrated support for the Exchange edge installation was almost too good to be true. I saw the opportunity to more easily control the web/mobile client access, and at the same time free up a couple of servers. We already had a third party EV SSL SAN certificate for TMG and Exchange. Longing back to ISA server I found the TMG to be a great product! At least while setting up access rules, web publishing and similar.

By now mailboxes had been moved to the Exchange 2010 box, and the 2007 box had been properly uninstalled. I removed the subscription for the first Exchange 2010 edge server, and subscribed to the TMG box which had been installed plainly with Exchange 2010 edge role, Forefront 2010 for Exchange and TMG, in that order.

At first we could receive e-mail but not send. After checking certificate installations, re-subscribing, repairing installations, and reading all I could find on the subject, it looked the like (according to some postings) the installation order somehow had been messed up after all. Removing and reinstalling all on the TMG (following notes/screenshots) simply made the sending of e-mail work instead of receiving.

The TMG server is a member server. This is the only thing I can think of not being straight from the recommendations. (We would of course prefer a separate dmz/edge domain with a one-way trust, and will consider that for later)
From what I have been reading the TMG can be joined to the internal domain, while it is recommended that a separate Exchange edge server is stand-alone or in a DMZ network. And the Exchange edge is recommended on the TMG. From this I make out that our setup is ok as long as we accept the security issue of exposing the Active Directory to an edge computer (for now).
Well, anybody know otherwise?
Any help would be very much appreciated.

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0
I'm running Exchange 2010 with only the Edge Transport-role on a Windows 2008 R2-server with Forefront TMG and Forefront Protection Manager for Exchange. I have an error message in application log every 1-2 minutes:

Log Name:      Application
Source:        Microsoft Forefront TMG Control
Date:          25.12.2009 21:05:28
Event ID:      31506
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      TMG.ad.artax.cz
Description:
Forefront TMG detected changes in Microsoft Exchange Server or Microsoft Forefront Protection configuration, and reapplied the e-mail policy configuration on server 'TMG'.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft Forefront TMG Control" />
    <EventID Qualifiers="32768">31506</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2009-12-25T20:05:28.000000000Z" />
    <EventRecordID>8101</EventRecordID>
    <Channel>Application</Channel>
    <Computer>TMG.ad.artax.cz</Computer>
    <Security />
  </System>
  <EventData>
    <Data>TMG</Data>
  </EventData>
</Event>

I am not changing anything. No error on Exchange server (Hub Transport) and everything seems to be working.

Could you help, please?

Best regards

Martin

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0

Sad to report this is not fixed.

 

Running TMG with SP!, exchange edge server with SP1, also Forefront for exchange edge server.

If i apply a change eg as in my post before (import a profanity list) TMG then overwrites it again, thus losing all the changes i made.

E-mail policy reapplied every 1-2 minutes - Error 31506 Microsoft Forefront TMG Control

$
0
0

Hi All

The Problem is now finally solved with Software Update 1 for TMG 2010 SP1 http://www.microsoft.com/downloads/en/details.aspx?FamilyID=695d0709-0d8b-45ee-afdb-727c4428ca4d

http://blogs.technet.com/b/isablog/archive/2010/09/20/software-update-1-for-microsoft-forefront-threat-management-gateway-tmg-2010-service-pack-1-now-available-for-download.aspx

I have also Updated the Exchange 2010 SP1 (Edge Role) on the TMG http://www.microsoft.com/downloads/details.aspx?FamilyID=50b32685-4356-49cc-8b37-d9c9d4ea3f5b&displaylang=de

No more errors since then :o)

Regards

Andres


-- MCSE 2003 MCSA 2003 Messaging MCITP: Enterpise Administrator MCTS: Windows Server 2008 MCTS: Exchange Server 2007 Configuration MCTS: Microsoft SQL Server 2005 VCP - VMWare Certified Professional
Viewing all 312 articles
Browse latest View live




Latest Images

Pangarap Quotes

Pangarap Quotes

Vimeo 10.7.0 by Vimeo.com, Inc.

Vimeo 10.7.0 by Vimeo.com, Inc.

HANGAD

HANGAD

MAKAKAALAM

MAKAKAALAM

Doodle Jump 3.11.30 by Lima Sky LLC

Doodle Jump 3.11.30 by Lima Sky LLC