There are already known issues with multi-homed AD's http://support.microsoft.com/support/kb/articles/Q181/7/74.ASP Placing your domain controller at the edge of the network is just asking for trouble. There's no such thing as the perfect firewall (as you probably know) and there are just too many people out there trying to get in to risk placing the core of your network that close to them. Jim Harrison MCP(2K), A+, Network+, PCG ----- Original Message ----- From: "Paul Nuernberger" <pen@xxxxxxxxx> To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> Sent: Thursday, August 02, 2001 09:35 Subject: [isalist] ISA Server & AD http://www.ISAserver.org A customer wants to run ISA Server on the same W2k server that is his AD primary controller. I've not found any direct information re: this issue. Can anyone on the list point out the various pro's & cons of doing this ? I'm still on the front side of the learning curve of ISA Server (run lots of *nix firewalls), so any help is greatly appreciated. I already use (& rely heavily upon) isaserver.org - super useful site. Paul Nuernberger Manager BARON Computers Inc. ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')