For all who like me may have struggled with this one: ISA server default settings do not allow inbound traffic to Mcafee VirusScan,Netshield,and Groupshield. First create a Protocal rule and give it a name, 1)Custom Protocol 2)FTP Download only 3)Schedule = Always 4)Apply to "Any Request" And save the new Rule Next Create 2 new Packet Filters as follows: Filter 1 1)Name: "Allow Connections to Ftp nai.com" 2)Description: As you wish 3)Filter Type "Custom" 4)Protocol "TCP" 5)Direction "Outbound" 6)Local Ports "All Ports" 7)Remote Ports "Fixed Port 21" 8)Applies to "Default IP Address's on External Interfaces" 9)Remote IP "All Machines" And Save Filter 2 1)Name: "Allow Connections to Ftp nai.com" 2)Description: As you wish 3)Filter Type "Custom" 4)Protocol "TCP" 5)Direction "Inbound" 6)Local Ports "All Ports" 7)Remote Ports "Fixed Port 20" 8)Applies to "Default IP Address's on External Interfaces" 9)Remote IP "All Machines" And Save Configure Mcafee product you wish to update in the Mcafee update properties box, to use your ISA server eg. <server name> port <8080> And Bingo Hope this helps Best regards to all at isalist, and thanks for all the help you have given me in the past. Rick Parsons rick@xxxxxxxxxxxxxxxxxx