Hi, I red an article from Tom about FTP and a tri homed ISA Server. Tom said that whan you want to have a FTP Server on a public DMZ, you have to create two paquet IP filtering: one for the port 21 for the DMZ, and another one from the port 20 of the FTP Server (if we use a FTP actif client). But, why create 2 filters, and not only one filter with a protocol definition with secondary connection ? thanks.