FwcTool.exe broken by SP1 client update - 3.Mar.2005 8:15:00 AM
FYI, once you update the SP1 firewall client, the separate firewall client control tool download which provides scripted control of the firewall client fails with the following error:
FwcTool version 4.0.2161 Firewall Client for ISA Server 2004 support tool Copyright (c) Microsoft Corporation. All rights reserved.
Action: Enable Firewall Client User: current Application: all applications
FwcTool failed. Error code 5, 70, 0x800706C6 Error Description: The array bounds are invalid.
When I run this on another test machine without the updated SP1 client is succeeds, both clients talking to a SP1 ISA server.
Note the build number of the tool which must be downloaded separately matches the pre-SP1 firewall client build number. Hopefully MS will release a new compatible build of this tool soon as I've seen this used a lot to manually control the firewall client. There are also a number of other separate utilities which I have not tested by suspect they may also fail.
No problem! Hey maybe you have contacts at MS to report it to? I tried emailing the "feedback" and they thought I wanted to report another IE bug! I can't seem to figure out what the official MS procedure is for the public to report a bug, etc. without paying at least $99.....which doesn't make sense for me to do since I know what the problem is and I know they have no immediate fix.
By the way, love the site you do an excellent job! I've been using the MS-ISA line of products since proxy 1.0 and this is by far the best real-world resource for the product line!
Tom, would appreciate a reply to this thread if you get some feedback re: fwctool. Hope it's fixed soon as it's holding up my rollout of the client.
Also, for existing ISA pre-SP1 FWC's, how can the update be applied. Does it require a re-install of the client or does it pull down the new client when SP1 is installed and the pre-SP1 FWC starts on the workstation? Doubt the latter, but one can hope. Assume I'll have to add another client install to my GPO.
WW, have you deployed the SP1 FWC using GPO? Do you know if it prevents that initial FWC window asking the user to click OK or cancel for how to connect to ISA (auto or manual)? Pre SP1 deployment of FWC via GPO is poor with that window popping up for the user, the first time they logon after the client is installed. It'd be great if SP1 FWC fixed this.
In the meantime I may continue to deploy pre SP1 client with fwctool and then install SP1 and redeploy FWC after they fix the fwctool.
Steve, SP1 does NOT fix the initial OK prompt. On pre-SP1, I got it everytime I logged on, but SP1 changes that to just 1 prompt on the first log on. Its fixable by just deleteing the shortcut in Start\All Programs\Startup. I created an MST file to remove it. You can create it pretty easily with Orca or download it from http://www.scottes.com/MS_FWC.zip
Actually the initial popup asking the user to configure the client has not changed at all from non-SP to SP1. Either way it only pops up once and as long as there is a valid configuration (auto or manual) and the user clicks ok it will not appear again.
I tried using the post SP1 FwcTool. Seems to have executed successfully, however, I see no change in the firewall client. The icon in the task bar does not have the normal red square to indicate that it's disabled, and if I right click, I still have the option of disabling it. I've rebooted the machine and still the same thing. Any idea's?