All Unit Monitors in Microsoft.Forefront.UAG Management Pack

 DisplayNameDescriptionIDTargetParent MonitorCategoryEnabledInstance NameCounter NameFrequencyAlert GenerateAlert SeverityAlert PriorityAlert Auto ResolveMonitor TypeRemotableAccessibilityRunAs
DirectAccess_Server_Activation.CriticalDirectAccess activation stateThis is a critical alarm generated because the DirectAccess activation process failed. This alarm is cleared when the DirectAccess activation process succeeds. DirectAccess_Server_Activation.CriticalMicrosoft.Forefront.UAG.DirectAccessSystem.Health.AvailabilityStateCustomTrue0TrueErrorHighTrueMicrosoft.Windows.2SingleEventLog2StateMonitorTypeTruePublic
DirectAccess_Server_Security_AuthFailuresIPv6_CriticalFailed Main Mode negotiations at critical levelThis is a critical alarm generated because the "Failed Main Mode Negotiations" counter (under the object "IPsec AuthIP IPv6" in the performance monitor tool) exceeded critical levels. This alarm is cleared when the counter returns to healthy levels. DirectAccess_Server_Security_AuthFailuresIPv6_CriticalMicrosoft.Forefront.UAG.DirectAccessSystem.Health.SecurityStateSecurityHealthTrueIPsec AuthIP IPv6Failed Main Mode Negotiations300FalseTrueSystem.Performance.DeltaThresholdTruePublic
DirectAccess_Server_Security_AuthFailuresIPv6_WarningFailed Main Mode negotiations at warning levelThis is a warning alarm generated because "Failed Main Mode Negotiations" counter (under the object "IPsec AuthIP IPv6" in the performance monitor tool) exceeded warning levels. This alarm is cleared when the counter returns to healthy levels. DirectAccess_Server_Security_AuthFailuresIPv6_WarningMicrosoft.Forefront.UAG.DirectAccessSystem.Health.SecurityStateSecurityHealthTrueIPsec AuthIP IPv6Failed Main Mode Negotiations300FalseTrueSystem.Performance.DeltaThresholdTruePublic
DNS64_Service_Average_Query_Processing_TimeDNS64 average query processing timeThis is a warning alarm generated because the "Total Query Average Processing Time" counter (under the object "Forefront UAG DNS64" in the performance monitor tool) exceeded a defined threshold. "Total Query Average Processing Time" is the average time taken for DNS64 to process a query. This alarm is cleared when the counter returns to healthy levels.DNS64_Service_Average_Query_Processing_TimeMicrosoft.Forefront.UAG.DNS64System.Health.PerformanceStatePerformanceHealthTrueForefront UAG DNS64Total Query Average Processing Time300FalseTrueSystem.Performance.ConsecutiveSamplesThresholdTruePublic
DNS64_Service_Total_DroppedDNS64 total dropped queriesThis is a warning alarm generated because the "Total Query Dropped" counter (under the object "Forefront UAG DNS64" in the performance monitor tool) exceeded a defined threshold. "Total Query Dropped" is the number of queries dropped by DNS64, usually due to full queues. This alarm is cleared when the counter returns to healthy levels.DNS64_Service_Total_DroppedMicrosoft.Forefront.UAG.DNS64System.Health.PerformanceStatePerformanceHealthTrueForefront UAG DNS64Total Query Dropped300FalseTrueSystem.Performance.DeltaThresholdTruePublic
DNS64_Service_Total_Dropped_SecondDNS64 total dropped queries per secondThis is a warning alarm generated because the "Total Query Dropped/sec" counter (under the object "Forefront UAG DNS64" in the performance monitor tool) exceeded a defined threshold. "Total Query Dropped/sec" is the number of queries dropped per second by DNS64, usually due to full queues. This alarm is cleared when the counter returns to healthy levels.DNS64_Service_Total_Dropped_SecondMicrosoft.Forefront.UAG.DNS64System.Health.PerformanceStatePerformanceHealthTrueForefront UAG DNS64Total Query Dropped/sec300FalseTrueSystem.Performance.ConsecutiveSamplesThresholdTruePublic
IPHTTPS_Gateway_AvailabilityIP-HTTPS gateway availabilityThis is a critical alarm generated because the IP Helper service (iphlpsvc) stopped responding. The IP Helper service provides tunnel connectivity using the Connectivity Platform, IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer. This alarm is cleared when the service is running again.IPHTTPS_Gateway_AvailabilityIPHTTPS_Gateway_ClassSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
ISATAP_Router_AvailabilityISATAP router availabilityThis is a critical alarm generated because the IP Helper service (iphlpsvc) stopped responding. The IP Helper service provides tunnel connectivity using the Connectivity Platform, IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer. This alarm is cleared when the service is running again.ISATAP_Router_AvailabilityISATAP_Router_ClassSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Microsoft.Forefront.UAG.DirectAccess.DAEngDriverMonitorNLB Helper driver availabilityThis is a critical alarm generated because the NLB Helper driver (DAEng) stopped responding. This alarm is cleared when the driver is running again.Microsoft.Forefront.UAG.DirectAccess.DAEngDriverMonitorMicrosoft.Forefront.UAG.DirectAccessSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Forefront.UAG.DirectAccess.NLB.DAEngDriverStateTruePublic
Microsoft.Forefront.UAG.DirectAccess.UserActivity.AtLeastOneStickyConnectionExistsSticky connections existThis is a warning alarm generated because there were no Network Load Balancing sticky connections on the current node. A "sticky" connection is a 6to4 or Teredo client connection that will always go to the same specific node. This alarm is cleared when at least one sticky connection is active.Microsoft.Forefront.UAG.DirectAccess.UserActivity.AtLeastOneStickyConnectionExistsMicrosoft.Forefront.UAG.DirectAccessMicrosoft.Forefront.UAG.DirectAccess.UserActivityPerformanceHealthTrue0FalseTrueMicrosoft.Forefront.UAG.DirectAccess.StickyConnectionsExistsTruePublic
Microsoft.Forefront.UAG.DirectAccess.UserActivity.AtLeastOneUserKerbMMSAExistsUser Kerberos Main Mode SAs existThis is a warning alarm generated because there were no established Main Mode security associations that have user Kerberos authentication.Microsoft.Forefront.UAG.DirectAccess.UserActivity.AtLeastOneUserKerbMMSAExistsMicrosoft.Forefront.UAG.DirectAccessMicrosoft.Forefront.UAG.DirectAccess.UserActivityPerformanceHealthTrue0FalseTrueMicrosoft.Forefront.UAG.DirectAccess.UserKerbMMSAExistsTruePublic
Microsoft.Forefront.UAG.DirectAccess.UserActivity.TeredoPacketReceiveRateTeredo packet receive rateThis is a warning alarm generated because there was no change in packet amount in the "In - Teredo Server Total Packets: Success + Error" counter (under the object "Teredo Server" in the performance monitor tool), meaning there was no Teredo traffic. This alarm is cleared when the counter returns to healthy levels.Microsoft.Forefront.UAG.DirectAccess.UserActivity.TeredoPacketReceiveRateMicrosoft.Forefront.UAG.DirectAccessMicrosoft.Forefront.UAG.DirectAccess.UserActivityPerformanceHealthTrueTeredo ServerIn - Teredo Server Total Packets: Success + Error600FalseTrueSystem.Performance.DeltaThresholdTruePublic
Microsoft.Forefront.UAG.DnsAlgSrvDNS64 DnsAlgSrv service availabilityThis is a critical alarm generated because the Forefront UAG DNS64 (DnsAlgSrv) service stopped responding. This alarm is cleared when the service is running again.Microsoft.Forefront.UAG.DnsAlgSrvMicrosoft.Forefront.UAG.DNS64System.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Microsoft.Forefront.UAG.Monitor.Application.BuiltInForefront UAG built-in application service availabilityThis is a critical alarm generated because a Forefront UAG built-in application service stopped responding. This alarm is cleared when the service is running again.Microsoft.Forefront.UAG.Monitor.Application.BuiltInMicrosoft.Forefront.UAG.Application.BuiltInMicrosoft.Forefront.UAG.Monitor.ApplicationsStateCollectionTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Microsoft.Forefront.UAG.Monitor.ConfigurationForefront UAG configuration module availabilityThis is a critical alarm generated because the Forefront UAG configuration module reported an error.Microsoft.Forefront.UAG.Monitor.ConfigurationMicrosoft.Forefront.UAG.ServerSystem.Health.AvailabilityStateAvailabilityHealthTrue0FalseTrueMicrosoft.Windows.2SingleEventLog2StateMonitorTypeTruePublic
Microsoft.Forefront.UAG.Monitor.RepositoryForefront UAG repository availabilityThis monitor represents a Forefront UAG repository. The repository is not monitored. A Forefront UAG repository holds information used to authenticate users accessing Forefront UAG portals.Microsoft.Forefront.UAG.Monitor.RepositoryMicrosoft.Forefront.UAG.RepositorySystem.Health.AvailabilityStateAvailabilityHealthTrue0FalseTrueMicrosoft.Windows.RepeatedEventLogSingleEventLog2StateMonitorTypeTruePublic
Microsoft.Forefront.UAG.Server.ConfigMgrComMonitorConfigMgrCom service availabilityThis is a critical alarm generated because the Forefront UAG Configuration Manager service (ConfigMgrCom) stopped responding. This alarm is cleared when the service is running again.Microsoft.Forefront.UAG.Server.ConfigMgrComMonitorMicrosoft.Forefront.UAG.ServerMicrosoft.Forefront.UAG.CoreServicesMonitorStateCollectionTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Microsoft.Forefront.UAG.Server.MonitorMgrComMonitorMonitorMgrCom service availabilityThis is a critical alarm generated because the Forefront UAG Monitoring Manager service (MonitorMgrCom) stopped responding. This alarm is cleared when the service is running again.Microsoft.Forefront.UAG.Server.MonitorMgrComMonitorMicrosoft.Forefront.UAG.ServerMicrosoft.Forefront.UAG.CoreServicesMonitorStateCollectionTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Microsoft.Forefront.UAG.Server.SessionMgrComMonitorSessionMgrCom service availabilityThis is a critical alarm generated because the Forefront UAG Session Manager service (SessionMgrCom) stopped responding. This alarm is cleared when the service is running again.Microsoft.Forefront.UAG.Server.SessionMgrComMonitorMicrosoft.Forefront.UAG.ServerMicrosoft.Forefront.UAG.CoreServicesMonitorStateCollectionTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Microsoft.Forefront.UAG.Server.UserMgrComMonitorUserMgrCom service availabilityThis is a critical alarm generated because the Forefront UAG User Manager service (UserMgrCom) stopped responding. This alarm is cleared when the service is running again.Microsoft.Forefront.UAG.Server.UserMgrComMonitorMicrosoft.Forefront.UAG.ServerMicrosoft.Forefront.UAG.CoreServicesMonitorStateCollectionTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Microsoft.Forefront.UAG.WatchDogSrvDNS64 WatchDogSrv service availabilityThis is a critical alarm generated because the Forefront UAG Watch Dog service (WatchDogSrv) stopped responding. This alarm is cleared when the service is running again.Microsoft.Forefront.UAG.WatchDogSrvMicrosoft.Forefront.UAG.DNS64System.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Network_Security_AvailabilityBFEBFE service availabilityThis is a critical alarm generated because the Base Filtering Engine service (BFE) stopped responding. The BFE service manages firewall and Internet Protocol security (IPsec) policies and implements user mode filtering. Disabling the BFE service significantly reduces the security of the system and also results in unpredictable behavior in IPsec management and firewall applications. This alarm is cleared when the service is running again.Network_Security_AvailabilityBFENetwork_Security_ClassSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Network_Security_AvailabilityIKEEXTIKEEXT service availabilityThis is a critical alarm generated because the IKE and AuthIP IPsec Keying Modules service (IKEEXT) stopped responding. The IKEEXT service hosts the Internet Key Exchange (IKE) and Authenticated Internet Protocol (AuthIP) keying modules which are used for authentication and key exchange in Internet Protocol security (IPsec). This alarm is cleared when the service restarts. Disabling the IKEEXT service disables IKE and AuthIP key exchange with peer computers. IPsec is typically configured to use IKE or AuthIP; therefore, stopping or disabling the IKEEXT service might result in an IPsec failure and might compromise the security of the system. This alarm is cleared when the service is running again.Network_Security_AvailabilityIKEEXTNetwork_Security_ClassSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Network_Security_ICMPQueueOverflow_WarningDiscarded ICMPv6 packets per secondThis is a warning alarm generated because the "Inbound Rate Limit Discarded ICMPv6 Packets/sec" counter (under the object "IPSec DOS Protection" in the performance monitor tool) exceeded a defined threshold. "Inbound Rate Limit Discarded ICMPv6 Packets/sec" is the rate at which ICMPv6 packets are received on a public interface and discarded because they exceeded the rate limit for ICMPv6 packets per second. This alarm is cleared when the counter returns to healthy levels.Network_Security_ICMPQueueOverflow_WarningNetwork_Security_ClassSystem.Health.PerformanceStatePerformanceHealthTrueIPsec DoS ProtectionInbound Rate Limit Discarded ICMPv6 Packets/sec300FalseTrueSystem.Performance.ConsecutiveSamplesThresholdTruePublic
Network_Security_IKEDoSPIKE DoS-prevention mode startedThis is a warning alarm for potential DoS attack and is raised when "IKE DoS-prevention mode started" event (Event Id: 4646, Event Source: Microsoft Windows security auditing, Event Log Channel: Security) is generated. This alarm is cleared when the same event is generated again.Network_Security_IKEDoSPNetwork_Security_ClassSystem.Health.SecurityStateSecurityHealthTrue0FalseTrueMicrosoft.Windows.2SingleEventLog2StateMonitorTypeTruePublic
Network_Security_QueueOverflow_WarningDiscarded IPv6 IPsec authenticated packets per secondThis is a warning alarm generated because the "Inbound Rate Limit Discarded IPv6 IPsec Authenticated Packets/sec" counter (under the object "IPSec DOS Protection" in the performance monitor tool) exceeded a defined threshold. "Inbound Rate Limit Discarded IPv6 IPsec Authenticated Packets/sec" is the rate at which authenticated IKEv1, IKEv2, AuthIP, or ESP IPv6 packets are received on a public interface and discarded because they exceed the rate limit for IPv6 IPsec authenticated packets per second. An authenticated packet is an IPsec packet with an associated state entry. A state entry is a pair of IPv6 addresses that is authorized to pass through from a public to an internal interface. This alarm is cleared when the counter returns to healthy levels.Network_Security_QueueOverflow_WarningNetwork_Security_ClassSystem.Health.PerformanceStatePerformanceHealthTrueIPsec DoS ProtectionInbound Rate Limit Discarded IPv6 IPsec Authenticated Packets/sec300FalseTrueSystem.Performance.ConsecutiveSamplesThresholdTruePublic
Network_Security_RateLimitDiscardUnAuthDiscarded IPv6 IPsec unauthenticated packets per secondThis is a warning alarm generated because the "Inbound Rate Limit Discarded IPv6 IPsec Unauthenticated Packets/sec" counter (under the object "IPSec DOS Protection" in the performance monitor tool) exceeded a defined threshold. "Inbound Rate Limit Discarded IPv6 IPsec Unauthenticated Packets/sec" is the rate at which unauthenticated IKEv1, IKEv2, AuthIP, or ESP IPv6 packets are received on a public interface and discarded because they exceed the rate limit for IPv6 IPsec unauthenticated packets per second. An unauthenticated packet is an IPsec packet without an associated state entry. A state entry is a pair of IPv6 addresses that is authorized to pass through from a public to an internal interface. This alarm is cleared when the counter returns to healthy levels.Network_Security_RateLimitDiscardUnAuthNetwork_Security_ClassSystem.Health.SecurityStateSecurityHealthTrueIPsec DOS ProtectionInbound Rate Limit Discarded IPv6 IPsec Unauthenticated Packets/sec300FalseTrueSystem.Performance.AverageThresholdTruePublic
Network_Security_ReplayAttackFailed replay detection packets per secondThis is a warning alarm generated because the "Packets That Failed Replay Detection/sec" counter (under the object "IPsec Driver" in the performance monitor tool) exceeded a defined threshold. "Packets That Failed Replay Detection/sec" is the rate of packets that contained an invalid sequence number since the computer was last started. Increases in this counter might indicate a network problem or replay attack. This alarm is cleared when the counter returns to healthy levels.Network_Security_ReplayAttackNetwork_Security_ClassSystem.Health.SecurityStateSecurityHealthTrueIPsec DriverPackets That Failed Replay Detection/sec300FalseTrueSystem.Performance.AverageThresholdTruePublic
Network_Security_SpoofingAttackIncorrect SPI packets per secondThis is a warning alarm generated because the "Incorrect SPI Packets/sec" counter (under the object "IPsec Driver" in the performance monitor tool) exceeded a defined threshold. "Incorrect SPI Packets/sec" is the rate of packets for which the Security Parameter Index (SPI) was incorrect since the computer was last started. A large number of packets with bad SPIs within a short amount of time might indicate a packet spoofing attack. This alarm is cleared when the counter returns to healthy levels.Network_Security_SpoofingAttackNetwork_Security_ClassSystem.Health.SecurityStateSecurityHealthTrueIPsec DriverIncorrect SPI Packets/sec300FalseTrueSystem.Performance.AverageThresholdTruePublic
Network_Security_StateUtil_CriticalCurrent state entries at critical levelThis is a critical alarm generated because the "Current State Entries" counter (under the object "IPSec DOS Protection" in the performance monitor tool) exceeded critical levels. "Current state Entries" is the number of active state entries in the table. A state entry is a pair of IPv6 addresses that is authorized to pass through from a public to an internal interface. This alarm is cleared when the counter returns to healthy levels.Network_Security_StateUtil_CriticalNetwork_Security_ClassSystem.Health.ConfigurationStateConfigurationHealthTrueIPsec DOS ProtectionCurrent State Entries300FalseTrueSystem.Performance.ConsecutiveSamplesThresholdTruePublic
Network_Security_StateUtil_WarningCurrent state entries at warning levelThis is a warning alarm generated because "Current State Entries" counter (under the object "IPSec DOS Protection" in the performance monitor tool) exceeded warning levels. "Current state Entries" is the number of active state entries in the table. A state entry is a pair of IPv6 addresses that is authorized to pass through from a public to an internal interface. This alarm is cleared when the counter returns to healthy levels.Network_Security_StateUtil_WarningNetwork_Security_ClassSystem.Health.ConfigurationStateConfigurationHealthTrueIPsec DOS ProtectionCurrent State Entries300FalseTrueSystem.Performance.ConsecutiveSamplesThresholdTruePublic
Router_6to4_Availability6to4 router availabilityThis is a critical alarm generated because the IP Helper service (iphlpsvc) stopped responding. The IP Helper service provides tunnel connectivity using the Connectivity Platform, IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer. This alarm is cleared when the service is running again.Router_6to4_AvailabilityRouter_6to4_ClassSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Teredo_Relay_AvailabilityTeredo relay availabilityThis is a critical alarm generated because the IP Helper service (iphlpsvc) stopped responding. The IP Helper service provides tunnel connectivity using the Connectivity Platform, IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer. This alarm is cleared when the service is running again.Teredo_Relay_AvailabilityTeredo_Relay_ClassSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic
Teredo_Server_AvailabilityTeredo server availabilityThis is a critical alarm generated because the IP Helper service (iphlpsvc) stopped responding. The IP Helper service provides tunnel connectivity using the Connectivity Platform, IPv6 transition technologies (6to4, ISATAP, Port Proxy, and Teredo), and IP-HTTPS. If this service is stopped, the computer will not have the enhanced connectivity benefits that these technologies offer. This alarm is cleared when the service is running again.Teredo_Server_AvailabilityTeredo_Server_ClassSystem.Health.AvailabilityStateAvailabilityHealthTrue0TrueErrorHighTrueMicrosoft.Windows.CheckNTServiceStateMonitorTypeTruePublic