Details, for one. 1. What's in the ISA logs for this new traffic? 2. Have you examined a capture to see what's happening on the wire? -------------------------------------------- Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/Jim_Harrison/ http://isatools.org Read the help / books / articles! -------------------------------------------- -----Original Message----- From: G.Waleed Kavalec [mailto:kavalec@xxxxxxxxx] Sent: Thursday, December 29, 2005 8:45 AM To: [ISAserver.org Discussion List] Subject: [isalist] Access Plus / ATT Easylink oddness http://www.ISAserver.org Some of our clients use Easylink Access Plus (formerly AT&T Easylink) which does secure mail and file transfer via port 992. We are testing a patch which (among other things) changes the url from secure-ua.gmis.att.net to secure-ua.gmis.easylink.com but leaves the port at 992. Machines behind our MS-ISA 2000 firewall, without the patch, can connect fine. A machines not behind our firewall, with or without the patch, can connect fine. But a patch machine behind the firewall cannot connect. Port remains 992, protocol rule for 993 outbound and inbound has worked for years, both urls resolve to the same IP address, and no mention of the url is anywhere in our rules. What am I missing? -- G. Waleed Kavalec ------------------------- Why are we all in this handbasket and where is it going so fast? ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx All mail to and from this domain is GFI-scanned.