Let me first say that I've read the article on the isaserver.org website on the complexities of ftp and the portion near the bottom where it gives the gloomy news about ftps, secureNat clients and ISA server. This is exactly where I'm at. I have an AS400 that needs to transmit information to and from EDS and another company using FTPS. The AS400 can't run the Firewall client so I created a client address set for it and the appropriate protocol rule, protocol definitions and matching packets filters for the required ports (990, 2015, 1969 and 1970; all in and out) and I disabled the FTP application filter and FTP packet filters that were in ISA by default so that they wouldn't get in the way. Attempts by the as400 to connect timeout. Not much is logged by the firewall - it shows 10.0.0.99 anonymous (this is the as400) connecting to the server in the log and all else are dashes. I went to all of this effort simply because in the article it isn't clear to me why non-firewall client computer can't access ftps. Can someone explain why not or give some advice on making it work? If I can't come up with a workable solution with the ISA server then it is going to be replaced by a Cisco Pix; this is the recommended hardware from EDS. I'd hate to see that happen. Amy