Can you turn on routing between the external and internal interfaces? If you can, and you can turn off NAT and all proxying, then the ISA becomes a simple stateful inspection packet filtering firewall, like a Checkpoint Firewall-1? We will implement the tri-homed ISA model. Thanks, Alex