Hi everyone, I am just testing a setup with ISA 2004 similar to the one recently published by Tom with an internal network, a public IP DMZ and and a private IP Perimeter network. I have a router with 2 Internet links in front of ISA (a 128k link for services (16 public IP addresses) and a 512k dynamic IP cable modem for users) Is it possible to make SNAT users (on the internal network) go out through one public IP and web proxy/firewall client users (also on the internal network) leave ISA through a different public IP address? What I wan't is the following, It is not unusual for the cable modem link to have intermitent failures, so if I can make web proxy clients leave the ISA with a public IP and and SNAT with a different public IP, then I can use the router to make them go out either through the cable modem or the 128k link on special ocations. (I think I could achieve this asigning 2 IP addreses to the external ISA interface) As it is a small company it would be quite easy to tell the users not to use proxy when the cable conection failed (it was done this way when there was no ISA) Is this possible??? Hope I explained myself if not please ask! Thanks, Alejandro Fernández Buenos Airess - Argentina