Still seeing errors against 10.ds.mrs.microsoft.com - the MRS site with the IIS8.5 holding page. Its slow to load in a browser, we get occasional, but regular, nslookup failures against it. We have been unable to trap any further details in TMG
Diagnostic Logging, but a Connectivity Test with detailed pathping gave us the following:
Time reported by the Microsoft Forefront TMG Firewall Service: 4.052 seconds
Testing https://10.ds.mrs.microsoft.com:443
Category: Connectivity error
Error details: 64 - The specified network name is no longer available.
whereas the same test for 10.ts.mrs.microsoft.com gives us...
Time reported by the Microsoft Forefront TMG Firewall Service: 0.273 seconds
HTTP response: 200 OK.
The test successfully completed for this URL.
It really looks like a DNS resolution issue against the 10.ds.mrs.microsoft.com MRS server (94.245.112.72 in the UK). Changing our ISP DNS forwarders hasn't helped, and we don't see DNS failures for other queries.
We're going to try switching the order of the MRS servers in the TMG "Microsoft Reputation Service Sites" object, within the Domain Name Sets group....