Hi, A client is running a few W3KSP1 servers, behind a W3KSP1 member server running ISA2004 with SP2 recently applied. The ISA server is a member server, and publishes the web site, e-mail, handles VPN/L2TP traffic, the other servers handle various combinations of DNS / WINS / Active Directory / Exchange / IIS /DHCP / Sharepoint / SQL200SP4 etc. The servers are well stocked on resources, Dual CPU, 2G ram, twin 36G mirrored drives for the OS, 5 36G R5 with on line spare for the data drives, on a separate array buss. I did not put the enviornment together, but it's a pleasure to work on, a prime example of "how to do things right". I have been maintaining the environment for about 8 months, and it performs flawlessly. Whoever put it together knew what hs was doing, and the company was willing to throw some money at it to do it right, and they reap the benefits from a very quite enironment. The only change made to the environment was to apply SP2 to the ISA server 3 weeks ago. The client FTP's data out to external companies at least half a dozen times a day, some of these transfers are fairly large at 100 - 150M zip'ed files. A couple of times a week, since the ISA was upgraded to SP2, a large FTP transfer will stall. Other FTP's at the same time are OK, and if the transfer is tried later it may again stall, or may be successfull. If they keep trying enough times, it will eventually work, but obviously this is very annoying for the user. The FTP client will eventually timeout, when the remote server times out the connection, but it sits there with no activity evident for 30 minutes before this occurs. The only apparent common thing is the SP2 upgrade on the ISA. The stall is not dependant on which workstation originates the transfer or which external company is receiving the file. The event logs on the servers / workstations / ISA server show nothing of interest around the time of the stall, the ISA server logs similarly show nothing of interest, there are no denied messages. A perfmon on both the workstations and ISA server show no hit of it being a resorce issue. The workstations are shut down each night, and so have a clean boot each morning, the servers have been rebooted twice. Has anyone seen anything similar, or have any ideas where the problem is, or even suggestions on what to look at ?