Hello, My reports are showing thousands of 'dropped packets' from Ip .211. This IP is assigned by DCHP to RRAS for VPN clients. Since we have not rolled out the VPN yet, and I have done any testing, I assume someone is trying to log on? Why do they show dropped? If the logon succeeds, it should pass the packets. If failure, they should not show up, right? BTW - Tom, Deb, great book. While I had a functioning ISA Server, the book gave me 3 pages of notes to check, and configs to change... Doug Evans Core Systems Plus, Inc. OKC - Tulsa devans@xxxxxxxxxxxxxx www.coreoffice.com