The company perimeter firewall is a W2003-R2 server running IsaServer-2006.
As always, it downloaded and installed the latest updates, and promptly stopped talking to the DMZ domain controllers (that run on a private maintenance LAN in the DMZ) and refused all RDP connections (presumably because it wouldn't authenticate).
Fortunately, the IsaServer is configured with a local configuration database, so it's not totally reliant on the DC and still operated, albeit not accepting any changes.
Much futzing about, I eventually tried backing out the latest update, just in case, and... bingo! everything starts to work again.
I believe that this is an SMB vulnerability, and this service is not exposed to the internet, but I'm now in two minds... play it safe and apply the update but not be able to access it except from the server room, or wait to see if there is a fix and/or workaround.
Anyone else have trouble with it, or is it just me ?