I like the previous idea better. Put the computer in a DMZ, and run whatever the heck you want, forget about trying to pass through ISA. That only requires one more NIC, and you don't have to go into the LinkSys/double-NAT fiasco. Only catch; you'd better reformat that computer before putting it back on the internal side of the ISA... If you absolutely HAVE to have it on the internal network, then take the below listed method and lock it down even more. Define exactly WHICH clients are allowed to connect with WHICH servers, with WHAT protocols. Then, in order to exploit those holes they have to impersonate those particular servers, and can only get to that one computer if they do. -----Original Message----- From: Steve Moffat [mailto:steve@xxxxxxxxxx] Sent: Thursday, April 07, 2005 14:17 To: [ISAserver.org Discussion List] Subject: [isalist] RE: Protocol question http://www.ISAserver.org OK Here we go Create 2 new protocols 1. port 3724 TCP outbound 2. port 3724 TCP inbound Create an allow rule using the above protocols for the pc that you are going to use to play the game, make sure the firewall client is installed. Start the game, monitor the isa logs to see what other ports are needed, inbound and outbound. Create protocols and add to the rule when needed. Jeez.......I got it working in 20 mins. S