Our website requires you install or enable flash player for full experience, you can download flash player by clicking here.
Make sure you also have javascript enabled so that flash player & menus work correctly.

Get Adobe Flash player

What would you like to monitor?

For when WebSpyrians have something to say.

Archive for the ‘Microsoft Threat Management Gateway’ Category

Vantage Update 2.2.0.68 (Exchange 2010, Juniper and IronPort Traffic Logs, and more)

Tuesday, January 25th, 2011

We have released an automatic update for the Vantage range of applications. This update includes some new loader formats, an experimental feature as well minor fixes and improvements.

Of note, this release includes full support for Microsoft Exchange 2010 Tracking logs (previously supported with the Exchange 2007 loader, but missing a few fields), as well as JunOS (Juniper) Traffic Logs, IronPort Traffic Monitor Logs and Squid Syslog. (more…)


Watch your TMG’s waist line. Switch log format and reduce fat now!

Wednesday, October 27th, 2010

We often recommend customers using Microsoft ISA or TMG switch their logging to W3C text file, in order to get the best possible import speed, and also because the text logs are much easier to access from a remote machine (see my previous article on accessing TMG’s SQL Express Log database). Logging to the default MSDE or SQL Express databases also requires more resources in terms of processor utilization, memory consumption and disk I/O.

But there is another advantage to switching to text. They take up considerably less disk space. Here are some figures:

(more…)


Vantage Update 2.2.0.51 (UrlCategory Fix for Microsoft TMG)

Thursday, August 26th, 2010

We have released an update to the Vantage range of applications to fix an issue with the Microsoft Forefront Threat Management Gateway (TMG) loader. (more…)


Vantage Update 2.2.0.50 (Juniper SA, Forefront Protection and more)

Monday, August 23rd, 2010

We have just released an auto update for the Vantage range of applications. This update includes support for the Juniper SA series and Microsoft Forefront Protection for Exchange 2010.

Here’s the full list of changes:

  • New: Juniper SA Series. Vantage can import and report on web traffic and VPN connections.
  • New: Microsoft Forefront Protection for Exchange 2010 format.
  • New: Avencis SSOx.
  • Improved: IronPort WSA: Department and Message fields were sometimes returned as null. Fixed.
  • Improved: Microsoft FTMG: Removed usage of deprecated “FilterInfo” field from W3C Web format.
  • Improved: Microsoft IAS Radius: Added support for Source/Destination IP and port (field code 5000).

(more…)


Vantage Update 2.2.0.48 – New Loaders, Features and Fixes

Thursday, July 29th, 2010

We’ve just released an update to the Vantage range of application, including the Web Module.

This release will be welcomed with open arms by many customers for the following reasons:

  • General usability improvements in the Web Module
    Multi-select / delete options, Ajax progress indicators to avoid page refreshes, export from Dynamics Report tab and more (see below)
  • Fixes to the Microsoft Forefront TMG loader
    See my other post: Microsoft Forefront TMG logs size fields the wrong way around. Also fixed ‘value cannot be null’ error when importing SQL logs.
  • Fixes to storage corruption issues
    This build should prevent ‘Normalization Index’ storage corruption issues from occurring. This often occurred after importing data, editing some log inputs and reimporting.
  • New loaders and more fixes
    See below for the full list

(more…)


Microsoft Forefront TMG logs size fields the wrong way around

Thursday, July 29th, 2010

If you’re using Microsoft Forefront Threat Management Gateway, there is a bug in the logging that causes Bytes Sent and Bytes Received to be logged in reverse. This seems to only affect the Web Proxy logs – both SQL and W3c . We noticed in a few web reports, that people were generally uploading a lot more than they were downloading. So we checked the logs and verified the buggy behavior: (more…)


Tips from TMG Expert: Changing WebSpy Vantage Scheduled Task Recurrence Interval

Monday, July 19th, 2010

Microsoft ISA Server and Forefront TMG users are probably familiar with isaserver.org’s informative news articles, tutorials, blogs and forums. I just wanted to bring your attention to one of isaserver.org’s contributing blog authors, Richard Hicks.

Richard has been working with Forefront Threat Management Gateway (TMG) 2010 and its predecessors for more than 12 years. He has designed and deployed network security solutions using TMG and ISA for SMB’s, military and defense organizations, and Fortune 500 companies around the world.

In addition to his isaserver.org blogs, Richard has his own ISA/TMG blog where he recently posted some useful tips on changing WebSpy Vantage’s scheduled task recurrence interval using the schtasks.exe command line tool. Adding more frequent import options (i.e. hourly) is on the product roadmap but until then, using the command line tool is a great alternative.
(more…)