I've done a couple of these configs and have had very good luck with the FB on the outside. Couple of notes: ISA needs to allow the WG admin ports (TCP/4103 and 4105) to the WG. I would recommend strongly to use real addresses on the WG int and ext. There are a couple of other notes of interest in the combination, but ISA tends to be more "internal network friendly" than the FB (also, you have to pay for the VPN client licenses, if that's something of interest to you). David -----Original Message----- From: Joseph [mailto:cismic@xxxxxxx] Sent: Mon 5/20/2002 9:58 AM To: [ISAserver.org Discussion List] Cc: Subject: [isalist] FIREBOX Placement http://www.ISAserver.org Hi all, I'm considering adding a firebox to my network. I recently had one given to Me and I've been reading the docs. Would it be best to have this located On the external side of the ISA machine or on the internal side of ISA? Thank you, Joseph ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: davidh@xxxxxxxxxxxx To unsubscribe send a blank email to leave-isalist-261457I@xxxxxxxxxxxxx