Microsoft small business knowledge base

Article ID: 2705829 - Last Review: May 4, 2012 - Revision: 1.0


Consider the following scenario:
  • You enable HTTPS inspection in the Web Access Policy on a server that is running Microsoft Forefront Threat Management Gateway (TMG) 2010.
  • You have clients that access Secure Sockets Layer (SSL) websites through Forefront TMG when a proxy server is not defined.
  • You installed a third-party web filter that calls the WriteClient API.

In this scenario, the Firewall service (Wspsrv.exe) in Forefront TMG may stop responding to all traffic until the Firewall service or the server is restarted.


This problem occurs because the call to the WriteClient API from a third-party web filter may cause a deadlock situation that blocks all worker threads in the Firewall service.


To resolve this problem, install the hotfix package that is described in the following Microsoft Knowledge Base article:
2689195  ( ) Rollup 2 for Forefront Threat Management Gateway (TMG) 2010 Service Pack 2


To work around this problem, use one of the following methods:
  • Disable the third-party web filter.
  • Disable HTTPS inspection.


Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.


For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
824684  ( ) Description of the standard terminology that is used to describe Microsoft software updates

  • Microsoft Forefront Threat Management Gateway 2010 Service Pack 2, when used with:
    • Microsoft Forefront Threat Management Gateway 2010 Standard
    • Microsoft Forefront Threat Management Gateway 2010 Enterprise
kbqfe kbfix kbexpertiseinter kbbug kbsurveynew KB2705829
Additional support options
Ask The Microsoft Small Business Support Community
Contact Microsoft Small Business Support
Find Microsoft Small Business Support Certified Partner
Find a Microsoft Store For In-Person Small Business Support