Have a read here: ISA Server Branch Office Policies Best Practices: ISA Server co-location with a domain controller<http://technet.microsoft.com/library/cc891503.aspx> It discusses the things you need to consider for domain traffic to, from and through ISA. Jim -----Original Message----- From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of James May Sent: Monday, November 17, 2008 10:03 AM To: isalist@xxxxxxxxxxxxx Subject: [isalist] Branch office Configuration Hello, I have recently removed a domain controller from the branch office. Is there a way to configure ISA so it will contact DC's in remote sites for windows user and groups? I can no longer logon to ISA server using domain credentials. Nor are a the user groups available for firewall rules. Does anyone know if it's possible to have ISA communicate securely with domain controllers on a remote subnet? Thanks, Jim May