Hello Thomas, First, thanks for your quick answer; unfortunately, the links you gave doesn't seems to do what we really want. In fact, we have in front of our firewall a traffic shaping device which we want to be able to allow more or less throughput to traffic depending on the originating internal subnet; so we need the firewall to be able to use always public IP address x to NAT subnet #1, always use public IP address #2 to NAT subnet 2 and so on... So, the question remains, is it feasible with ISA and if so, how?