Drop the gateway in the internal interface; "There can be only one". If you need to converse with multiple internal subnets, then you should add manual routes. Bear in mind that if RRAS is installed, you should enter them there. Also, make sure you bind the internal NIC first. Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://www.microsoft.com/isaserver http://isaserver.org/Jim_Harrison http://isatools.org Read the help, books and articles! ----- Original Message ----- From: "Stephen Revel" <silimonkey@xxxxxxxxxxx> To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> Sent: Sunday, February 02, 2003 20:40 Subject: [isalist] External Connection Shutdown http://www.ISAserver.org This started rather abruptly. After recieving multiple IP Spoof alerts and Multiple Dropped Packet alerts. The external interface that connects to the Cisco router stops sending and recieving data. After rebooting the server connection is re-established for my network, but after more IP Spoof alerts and Dropped packet alerts the external interface stops transmiting data to the router again as requires another reboot. The spoof attacks are all coming from exteranl sources, but the dropped packet alerts are coming from the external card on the isa server that is connected directly to the cisco router. Here is my ip scheme and an ipconfig /all for internal and external nics. All ip's are hard coded. Cisco external 144.x.x.x Cisco Internal 10.27.8.1 Isa External 10.27.8.2 Isa Internal 172.16.0.1 External nic (all ip's are hard coded) Ip address- 10.27.8.2 Mask- 255.255.255.0 Default gateway- 10.27.8.1 DNS servers- 199.2.252.10 204.214.7.10 Ip address- 172.16.0.1 Mask- 255.255.255.0 Default gateway- 172.16.0.1 DNS servers- 199.2.252.10 204.214.7.10 Thanks Stephen ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Exchange Server Resource Site: http://www.msexchange.org/ Windows Security Resource Site: http://www.windowsecurity.com/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')