Microsoft KB Archive/943626

= Warning event 9508 is logged in the Application log on a cluster system that is running Forefront Security for Exchange Server =

Article ID: 943626

Article Last Modified on 11/9/2007

-

APPLIES TO


 * Microsoft Forefront Security for Exchange Server

-



INTRODUCTION
This article includes information about the following Warning event that is generated by the Microsoft Forefront Server Security CCR Replication service (FSECCRservice):

Event Type: Warning

Event Source: FSECCRService

Event Category: CCR Service

Event ID: 9508

Date:

Time:

User: N/A

Computer:

Description:

Microsoft Forefront Server Security CCR Replication service has skipped replication of an engine.

Engine: WormList

Reason: An error occurred while obtaining the Forefront Run lock and the Engine Update lock.

For more information, see Help and Support Center at

http://go.microsoft.com/fwlink/events.asp

This event is frequently logged in the Application log of the cluster nodes of a Microsoft Exchange Server 2007 Cluster Continuous Replication (CCR) cluster system that is running Forefront Security for Exchange Server.



MORE INFORMATION
You receive Warning event 9508 when the FSCcontroller service and other related Forefront services are running on a passive node of a CCR cluster system. In a CCR cluster system, the only Forefront service that runs on the passive nodes is the FSECCRservice. The FSECCRservice is responsible for the replication of data between the active node and a passive node. By default, Forefront Security engines that are running on the passive nodes of a CCR cluster system are updated by an active node. You can change the behavior by using the Redistribution Server option that is available under General Options in the Forefront Server Security Administrator Console.

You can connect directly to the passive node of a CCR cluster only to access the quarantine information. But you must not make any other configuration changes in the Forefront Security for Exchange Server installation on the passive node. When you connect directly to a passive node, you use the Forefront Server Security Administrator on the passive node to access the quarantine information. This starts the FSCcontroller service and other related Forefront services on the passive node. When the FSCcontroller service is started on the passive node, the lock will be set, and the Forefront replication between the nodes will fail. After you close the Forefront Server Security Administrator Console, the Forefront services on the passive node stop, and the replication between the nodes resumes again.

Also, replication of Forefront data between two nodes may fail if you use the Forefront Server Security Management Console (FSSMC) to manage a CCR cluster. When you use the FSSMC to poll a passive node, the FSSMC runs the FSCcontroller service on the passive node. This behavior interrupts the replication of Forefront data between the nodes for a short time. The replication of Forefront data between the nodes starts again after the FSCcontroller service stops.

Keywords: kbhowto kbinfo kbexpertiseadvanced KB943626

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.