Hey Dan, That is true. If the client isn't configured as a Firewall client, then without a default gateway configured, it will only be able to get Internet access for Web proxied protocols (HTTP/HTTPS/HTTP tunneled FTP). HTH, Tom www.isaserver.org/shinder Tom and Deb Shinder's Configuring ISA Server 2004 http://tinyurl.com/3xqb7 MVP -- ISA Firewalls -----Original Message----- From: Ball, Dan [mailto:DBall@xxxxxxxxxxx] Sent: Wednesday, March 30, 2005 8:27 AM To: [ISAserver.org Discussion List] Subject: [isalist] RE: possible fix ISAserver.org - Review of SurfControl Web Filter 5.0 for ISA Server 2004 http://www.ISAserver.org Just hypothetically, since SecureNAT requires the "default gateway" to operate, what would be the ramifications of leaving the default gateway blank on DHCP? That would kill off any program that wasn't capable of using a proxy server. I tried one workstation here with a blank setting, and it appears that only ICMP was affected (and only for external sites). Otherwise, everything seemed to be working fine. I know there would be an issue with multiple subnets, but I would think that could be handled with a ROUTE ADD command in the login script, or other similar technique. ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: World of Windows Networking: http://www.windowsnetworking.com Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: tshinder@xxxxxxxxxxxxxxxxxx To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist Report abuse to listadmin@xxxxxxxxxxxxx