Hi Christian, ACK! ;-) Tom Thomas W Shinder www.isaserver.org/shinder ISA Server and Beyond: http://tinyurl.com/1jq1 Configuring ISA Server: http://tinyurl.com/1llp -----Original Message----- From: Christian.Schramm@xxxxxxxxxxxxxx [mailto:Christian.Schramm@xxxxxxxxxxxxxx] Sent: Friday, May 23, 2003 10:05 AM To: [ISAserver.org Discussion List] Subject: [isalist] RE: ISA in DMZ with authentication by Domain (with DC i n internal network) http://www.ISAserver.org Summary: If your ISA server is a standalone, than you can not use authentication with any domain... Maybe you can manually create local users and authenticate them ... If you want to join your ISA to your internal W2K domain and have a hardware packet filter in between, then open up the ports regarding W2K log-on mentioned in the KB article http://support.microsoft.com:80/support/kb/articles/Q280/1/32.ASP&NoWebC ontent=1 <http://support.microsoft.com/support/kb/articles/Q280/1/32.ASP&NoWebCon tent=1> If you want to join your ISA to you internal W2K domain and have another ISA in between, then KB article http://support.microsoft.com/default.aspx?scid=kb;en-us;Q329807 is the one for you... ACK, Tom? ;-) Have a nice weekend... Christian