Hi Allen, The ISA Server needs to be ad the edge of the private network. Put the CK box external to the ISA Server. That way you can take advantage of ISA Server's user/group based access controls. HTH, Tom Thomas W Shinder www.isaserver.org/shinder ISA Server and Beyond: http://tinyurl.com/1jq1 Configuring ISA Server: http://tinyurl.com/1llp -----Original Message----- From: Allan [mailto:allanls@xxxxxxxxxxx] Sent: Wednesday, March 12, 2003 1:04 AM To: [ISAserver.org Discussion List] Subject: [isalist] Firewall client communication with ISA Server through checkpoint http://www.ISAserver.org Hi, I have the following setup: Firewall Client <-> Checkpoint <-> ISA Server. I have created the following rule on the checkpoint firewall: From Firewall Client To Isa Server Allow Port 1745. However when I try to browse the internet from the machine where i have installed the firewall client, I am unable to do so. From netstat i have been able to gather that the firewall client connects to the isa server on some dynamic ports apart from 1745. How do i configure the firewall client to connect to the isa server on some specific ports? Any help or suggestions in this direction would be helpful. Regards Allan L. ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Exchange Server Resource Site: http://www.msexchange.org/ Windows Security Resource Site: http://www.windowsecurity.com/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: tshinder@xxxxxxxxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')