You can do this simply by setting the below registry key.
Key: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server
Once set reboot the server and SSL 2.0 will be disabled
NLB can be configured to work in either unicast or multicast mode. These modes determine how the cluster assigns itself MAC addresses. The upstream router needs to send packets destined for the cluster based on the MAC address advertised by the cluster. The cluster MAC address needs to be the same for all virtual IP addresses because all packets destined for a virtual IP address must be delivered to all members of the NLB array.
Starting with Rollup 4 you get them all cummulative.
TMG SP2 can be applied for TMG SP1 with Update 1 and covers all too.
Be aware, that rollups for Forefront TMG 2010 SP1 are not cummulative. So you need to install every rollup after the other in right order.