Good information, Thx Tom So it seems I was right, isn't it. But u did not told about order of applying the rules in IP Packet Filter section. And, at last I seems ISA Server is not a good choice for advanced policy routing and perfect NAPT & NAT and also filtering. ISA Server is an integrated Product for different level of filtering and routing. Good effort, but has way to progress. But 2004 version seems really nice job. It's integration makes it confusing for me, at least as a newbie. I'm very familiar w/ Netfilter/IPtables Architecture. It's great, ther is no confusing problem w/ iptables. But I should appreciate MS guyz for ISA Server 2004, very improved. Regards Radien