That setting has no effect on ISA NAT. VPN clients cannot be SecureNAT clients and SecureNAT clients can't have "all IP protocol" access without creating a protocol definition that includes all protocols between 1 and 65535. ISA was designed to place access controls across its borders. If you don't want the controls, then why are you using ISA? Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://www.microsoft.com/isaserver http://isaserver.org/Jim_Harrison http://isatools.org Read the help, books and articles! ----- Original Message ----- From: "Rui Silva" <rui.silva@xxxxxxxxxxx> To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx> Sent: Monday, December 22, 2003 08:43 Subject: [isalist] ISA-NAT: Advanced configuration http://www.ISAserver.org I have an ISA Server configured as a VPN Gateway. This machine has an external interface with a public IP address and an internal interface with private address. I would like to enable internet conectivity for the VPN clients (all IP traffic, not only HTTP through web proxy). In order to do this I know I have to modify the NAT configuration. Microsoft has an article that explains this procedure for RRAS: http://support.microsoft.com/default.aspx?scid=kb;en-us;Q310888 Does anyone know a similar solution for the ISA Server NAT? txs ------------------------------------------------------ List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ ------------------------------------------------------ Other Internet Software Marketing Sites: Leading Network Software Directory: http://www.serverfiles.com No.1 Exchange Server Resource Site: http://www.msexchange.org Windows Security Resource Site: http://www.windowsecurity.com/ Network Security Library: http://www.secinf.net/ Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: jim@xxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')