<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/MU" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: WARNING! Windows Server 2003 SP2 May Destroy Your ISA Firewall without Warning</title>
	<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/</link>
	<description>Written by Dr Thomas W Shinder, consultant to Microsoft, HP and many Fortune 500 companies on ISA firewall and Web proxy deployments this blog is where administrators get information about ISA Server Universal Threat Management firewalls. Topics include how to manage, deploy, and troubleshoot ISA Server as a network firewall, Web proxy/Web cache, remote access VPN server and VPN gateway to provide a high level of network security for all corporate computers.</description>
	<pubDate>Fri, 10 Oct 2008 23:00:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>

	<item>
		<title>by: Ryan</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-199054</link>
		<pubDate>Wed, 30 Jul 2008 21:53:31 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-199054</guid>
					<description>Does this affect ISA 2006 SP1?  I didn't see any mention in the release notes.  Is it a good idea to just disable it anyway?

Thanks!</description>
		<content:encoded><![CDATA[<p>Does this affect ISA 2006 SP1?  I didn&#8217;t see any mention in the release notes.  Is it a good idea to just disable it anyway?</p>
<p>Thanks!
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jake16</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-167027</link>
		<pubDate>Thu, 13 Mar 2008 03:01:33 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-167027</guid>
					<description>Hi,

Any update on this?

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Any update on this?</p>
<p>Thanks
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Michaelm</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-154797</link>
		<pubDate>Wed, 30 Jan 2008 23:24:29 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-154797</guid>
					<description>Thanks a million for Eric's solution. Worked a charmed. Saved a disaster, having the server back up with 30 mins.

Thanks again for your invaluable post.</description>
		<content:encoded><![CDATA[<p>Thanks a million for Eric&#8217;s solution. Worked a charmed. Saved a disaster, having the server back up with 30 mins.</p>
<p>Thanks again for your invaluable post.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: abhinaw</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-141778</link>
		<pubDate>Mon, 03 Dec 2007 15:44:26 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-141778</guid>
					<description>we faced this problem of RSS( TOE, Offload etc ) with Windows 2003 Sp2 and old BroadCom NIC. we updated the NIC to the latest one with RSS support. Broadcom BCM5708C Nextreme GigE. Driver date 4/4/2006, version 2.6.14.0.
We have RSS disabled with registry changes and now we are getting error as published by microsoft  in this article -----http://support.microsoft.com/kb/910904-----

&quot;The average call duration has exceeded 10 minutes. If this is not the expected behavior, please see article 910904 in the Microsoft Knowledge Base at http://support.microsoft.com for details on how to use the COM+ AutoDump feature to automatically generate dump files and/or terminate the process if the problem occurs again.&quot;

Appreciate any feed back on this issue.
thanks
-abhinaw</description>
		<content:encoded><![CDATA[<p>we faced this problem of RSS( TOE, Offload etc ) with Windows 2003 Sp2 and old BroadCom NIC. we updated the NIC to the latest one with RSS support. Broadcom BCM5708C Nextreme GigE. Driver date 4/4/2006, version 2.6.14.0.<br />
We have RSS disabled with registry changes and now we are getting error as published by microsoft  in this article &#8212;&#8211;http://support.microsoft.com/kb/910904&#8212;&#8211;</p>
<p>&#8220;The average call duration has exceeded 10 minutes. If this is not the expected behavior, please see article 910904 in the Microsoft Knowledge Base at <a href='http://support.microsoft.com' rel='nofollow'>http://support.microsoft.com</a> for details on how to use the COM+ AutoDump feature to automatically generate dump files and/or terminate the process if the problem occurs again.&#8221;</p>
<p>Appreciate any feed back on this issue.<br />
thanks<br />
-abhinaw
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Rhodzer</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-109586</link>
		<pubDate>Wed, 25 Jul 2007 12:25:48 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-109586</guid>
					<description>Had failed teaming after update to SP2 with Intel pro 1000 MT dual card. Had to install the latest pro2kxp utility, then it still did not work. tried uninstalling each card individually - no joy.

Have then uninstalled the software (deleting the network connections) logged into the server at it's physical location, re-scanned for hardware, picked up the two NIC's. THen installed the pro2kxp software utility and magically everything is now working and the teaming options are available through comp man.

cheers,
Rhodzer.</description>
		<content:encoded><![CDATA[<p>Had failed teaming after update to SP2 with Intel pro 1000 MT dual card. Had to install the latest pro2kxp utility, then it still did not work. tried uninstalling each card individually - no joy.</p>
<p>Have then uninstalled the software (deleting the network connections) logged into the server at it&#8217;s physical location, re-scanned for hardware, picked up the two NIC&#8217;s. THen installed the pro2kxp software utility and magically everything is now working and the teaming options are available through comp man.</p>
<p>cheers,<br />
Rhodzer.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Neil Pearson</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-104100</link>
		<pubDate>Tue, 19 Jun 2007 13:18:26 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-104100</guid>
					<description>Hi All,

I have installed SP2 on an ISA 2004 with SP3. I have had no problems so far.

Rgds,

Neil</description>
		<content:encoded><![CDATA[<p>Hi All,</p>
<p>I have installed SP2 on an ISA 2004 with SP3. I have had no problems so far.</p>
<p>Rgds,</p>
<p>Neil
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Sam</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-99147</link>
		<pubDate>Thu, 31 May 2007 07:22:24 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-99147</guid>
					<description>Hi Tom , 

I'm running ISA 2006 and smartfilter as content filtering which worked like a champ . Lately I've updated my server with win 2003 sp2 and I'm running into some strange networking problems .ISA stop network communications intermittently.I'm disabled  the RSS registry key but the problem remain the same. Finally I've uninstalled win 2003 sp2 but the problem remain the same.I don't know what changes has been made to my isa server even after uninstalling win 2003 sp2 .

Please help !!!

Sam</description>
		<content:encoded><![CDATA[<p>Hi Tom , </p>
<p>I&#8217;m running ISA 2006 and smartfilter as content filtering which worked like a champ . Lately I&#8217;ve updated my server with win 2003 sp2 and I&#8217;m running into some strange networking problems .ISA stop network communications intermittently.I&#8217;m disabled  the RSS registry key but the problem remain the same. Finally I&#8217;ve uninstalled win 2003 sp2 but the problem remain the same.I don&#8217;t know what changes has been made to my isa server even after uninstalling win 2003 sp2 .</p>
<p>Please help !!!</p>
<p>Sam
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: the back room tech Windows 2003 SP2 problems on Windows 2003 SBS servers &#171;</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-97514</link>
		<pubDate>Sat, 26 May 2007 15:31:37 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-97514</guid>
					<description>[...] Before you install this service pack on a SBS 2003 server, read the official release notes. Then, read Susan Bradley&amp;#8217;s unofficial release notes, which detail the proper way to apply the update. Update your NIC drivers, especially for Broadcom NICs prior to installation.   Posted in troubleshooting, SBS, patches, upgrade, best practices, Windows. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Before you install this service pack on a SBS 2003 server, read the official release notes. Then, read Susan Bradley&#8217;s unofficial release notes, which detail the proper way to apply the update. Update your NIC drivers, especially for Broadcom NICs prior to installation.   Posted in troubleshooting, SBS, patches, upgrade, best practices, Windows. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Thomas Shinder</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-97347</link>
		<pubDate>Thu, 24 May 2007 14:37:27 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-97347</guid>
					<description>Hi Jim,

Probably, but hard to say for sure without actually testing it.

Tom</description>
		<content:encoded><![CDATA[<p>Hi Jim,</p>
<p>Probably, but hard to say for sure without actually testing it.</p>
<p>Tom
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Jim Mulvey</title>
		<link>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-97263</link>
		<pubDate>Wed, 23 May 2007 21:40:34 +0000</pubDate>
		<guid>http://blogs.isaserver.org/shinder/2007/03/23/warning-windows-server-2003-sp2-may-destroy-your-isa-firewall-without-warning/#comment-97263</guid>
					<description>As I understand it from the Microsoft article here: http://support.microsoft.com/?id=927695 the problem is that both SP2 and the NIC are trying to perform Receive Side Scaling.

The documentation I've read from Microsoft here http://www.microsoft.com/whdc/device/network/NDIS_RSS.mspx says, &quot;Thus a software implementation of RSS could make the system perform worse than if RSS were not enabled. As a result, implementations should not support RSS if the network adapter cannot generate the hash result.&quot;

So, this suggests to me that the registry change which disables RSS at the software level would be the preferred approach and would ensure you still get the benefits of hardware RSS without the performance degradation of having your CPU handle the cryptographic hashing.

Comments?</description>
		<content:encoded><![CDATA[<p>As I understand it from the Microsoft article here: <a href='http://support.microsoft.com/?id=927695' rel='nofollow'>http://support.microsoft.com/?id=927695</a> the problem is that both SP2 and the NIC are trying to perform Receive Side Scaling.</p>
<p>The documentation I&#8217;ve read from Microsoft here <a href='http://www.microsoft.com/whdc/device/network/NDIS_RSS.mspx' rel='nofollow'>http://www.microsoft.com/whdc/device/network/NDIS_...S.mspx</a> says, &#8220;Thus a software implementation of RSS could make the system perform worse than if RSS were not enabled. As a result, implementations should not support RSS if the network adapter cannot generate the hash result.&#8221;</p>
<p>So, this suggests to me that the registry change which disables RSS at the software level would be the preferred approach and would ensure you still get the benefits of hardware RSS without the performance degradation of having your CPU handle the cryptographic hashing.</p>
<p>Comments?
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
