I'm seeing repeated denied connections from the internal ISA NIC to the backend Exchange server in ths ISA logs. They all have source port of 5 and destination of 1 and show protocol as "unidentified ip traffic". result code is "0xc004000d FWX_E_POLICY_RULES_DENIED". Anyone have an idea what might be wrong? ISA 2004 SP1, Exchange 2003 SP2. I have OWA published from FE and RPC over HTTP set up. Also have POP3S and SMTPS published, but no one is using it. Inbound SMTP is going to the FE server. thanks, Jeff