| DisplayName | Description | ID | Target | Enabled | Frequency | Remotable |
| IP-HTTPS gateway discovery | IP-HTTPS is a new protocol for Windows 7 and Windows Server 2008 R2 that allows hosts behind a Web proxy server or firewall to establish connectivity by tunneling IPv6 packets inside an IPv4-based HTTPS session. HTTPS is used instead of HTTP to prevent Web proxy servers from examining the data stream and terminating the connection.
Discovery of the IP-HTTPS gateway happens only if the machine is discovered as a DirectAccess server. The registry key HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\iphttps\iphttpsinterface\InterfaceRole, value=1 is checked. This key is automatically created during the configuration of the DirectAccess server. | IPHTTPS_Gateway_Discovery | Microsoft.Forefront.UAG.DirectAccess | True | 14400 | False |
| ISATAP router discovery | ISATAP (RFC 4214) is an IPv6 transition technology that is used to provide IPv6 connectivity between IPv6/IPv4 hosts across an IPv4-only intranet. ISATAP can be used for DirectAccess to provide IPv6 connectivity to ISATAP hosts across your intranet. | ISATAP_Router_Discovery | Microsoft.Forefront.UAG.DirectAccess | True | 14400 | False |
| Network security discovery | Network Security component uses IPsec policies for authentication and encryption of DirectAccess connections. Discovery of the network security component happens only if the machine is discovered as a DirectAccess server. Discovery occurs when the following event is generated: STATUS_IPSEC_DOSP_INSTALLED (Id.: 1020), Event Source: Microsoft-Windows-WFP, Event Log Channel: Microsoft-Windows-WFP/Operational. | Microsoft.Forefront.UAG.DirectAccess.NetworkSecurityDiscovery | Microsoft.Forefront.UAG.DirectAccess | True | 14400 | False |
| DirectAccess discovery | DirectAccess is an optional feature of Windows Server 2008 R2 that will host, manage, and either terminate or pass-through IPsec sessions. The DirectAccess server is a server function and cannot be installed on a client computer running Windows 7.
Discovery of DirectAccess happens only if the machine is discovered as a Forefront UAG server. The registry key HKLM\Software\WhaleCom\e-Gap\Configuration\DirectAccess\MachineState, value=1 is checked. This key is automatically created during the configuration of the Forefront UAG server. | Microsoft.Forefront.UAG.DirectAccessDiscovery | Microsoft.Forefront.UAG.Server | True | 14400 | False |
| Forefront UAG server discovery | Forefront UAG server represents an installation of Forefront UAG on a server machine.
Discovery of Forefront UAG server is triggered by the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{9B0CE58E-C122-4CB4-80C1-514D4162C07C}. This key is automatically created during the installation of Forefront UAG. | Microsoft.Forefront.UAG.Discovery.Server | Microsoft.Windows.Server.Computer | True | 14400 | False |
| DNS64 discovery | DNS64 complements a NAT64 deployment by translating IPv4 DNS responses to IPv6 DNS responses according to a predefined NAT64 prefix.
Discovery of the DNS64 component happens only if the machine is discovered as a DirectAccess server. The registry key HKLM\Software\WhaleCom\e-Gap\Configuration\DirectAccess\Received\DNS64_State, value=1 is checked. This key is automatically created during the configuration of the DirectAccess server. | Microsoft.Forefront.UAG.DNS64Discovery | Microsoft.Forefront.UAG.DirectAccess | True | 14400 | False |
| Forefront UAG trunks, applications, and repositories discovery | A Forefront UAG trunk groups Forefront UAG applications for publishing with Forefront UAG repositories for authentication.
Discovery of Forefront UAG trunks, applications, and repositories happens only if the machine is discovered as a Forefront UAG server. For each configured trunk, application, and repository, an appropriate class is discovered. Information is extracted from the Forefront UAG COM objects. | Microsoft.Forefront.UAG.TrunksDiscovery | Microsoft.Forefront.UAG.Server | True | 14400 | False |
| 6to4 router discovery | 6to4 (RFC 3056) is an IPv6 transition technology that provides IPv6 connectivity across the IPv4 Internet for hosts or sites that have a public IPv4 address. | Router_6to4_Discovery | Microsoft.Forefront.UAG.DirectAccess | True | 14400 | False |
| Teredo relay discovery | Teredo (RFC 4380) is an IPv6 transition technology that provides IPv6 connectivity across the IPv4 Internet for hosts that are located behind an IPv4 network address translation (NAT) device and are assigned a private IPv4 address. | Teredo_Relay_Discovery | Microsoft.Forefront.UAG.DirectAccess | True | 14400 | False |
| Teredo server discovery | Teredo (RFC 4380) is an IPv6 transition technology that provides IPv6 connectivity across the IPv4 Internet for hosts that are located behind an IPv4 network address translation (NAT) device and are assigned a private IPv4 address. | Teredo_Server_Discovery | Microsoft.Forefront.UAG.DirectAccess | True | 14400 | False |