Thanks Dan I did create a rule allowing Symantec it didn't work I guess I jumped the gun it was the http filter blocking the .zip file extension. Thanks again for your reply. jim From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of Ball, Dan Sent: Friday, October 23, 2009 9:11 AM To: 'isalist@xxxxxxxxxxxxx' Subject: [isalist] Re: firewall client Just create a rule allowing traffic to the Symantec update site. From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of Jim Sent: Friday, October 23, 2009 9:44 AM To: isalist@xxxxxxxxxxxxx Subject: [isalist] firewall client Hello All, I have a client using ISA 2006 I have several rules restricting internet access. I use the http filter to block unwanted file extensions and I also have a restricted protocol set. My question is this currently all workstations are secure nat clients. I recently have installed Symantec end point security and there is no parent server due to hardware restrictions. If I install firewall client can I allow only end point security to update without reducing my current rule set? Thanks in Advance, Jim