Nick, I think your saying that your problem is SSL connections are unreliable when going through ISA right? Your correct in that SSL connections by default shouldn't be cached... I can only think that the added overhead introduced when ISA is used may be timing out the TCP connection. To determine which end is giving up try logging both blocked AND allowed packets then look at the Packet Filter logs to see if you can determine it from there otherwise you will need to capture some packets to see exactly what's causing the prob. OR Have you set your browser's proxy settings to ISA? (it should still work if you do NOT provided you've got the HTTP redirector application filter enabled) but this may introduce the latency that's causing your timeouts. Nigel TechBase Perth