Hi, The Situation: We have internet leased line at the Head office and all branch offices connect to the head office for internet access. I'm in the process of designing a firewall architecture and Proxy services using ISA server. My internet firewall is Nokia Checkpoint and i plan to use ISA server as the internal firewall (2nd tier firewall) Design: I plan to setup ISA Enterprise edition in the integrated mode (firewall and caching) to form an Array at the head office with a ISA standard edition for caching on the branch office. I want to use hierarchical chaning of the servers between the branch office and the head office. Questions 1) Has anyone got a similar working implementation? 2) I believe that at the client at the branch office will be configured to pint to the local ISA server and the local ISA server will point to head office array name and the requests go to the alternate ISA servers for load balancing is that correct? If so what routing basis does the array use to manage to send these requests to the alternate ISA servers in the array. 3) We are planning to setup the ISA server in the branch office on a domain controller which is also and AD integrated DNS server. Is anyone aware of any problems related to this since i saw an article about this on ISAserver.org site. Any inputs would be appreciated. Cheers!!! 3)