Hi Mihnea, 1. The packet filter is necessary because the ISA server itself is sourcing the connection to the time server. 2. The site and content rule is necessary if you dont have any other allow rule. 3. What time server are you using? I'm using tick or tock.usno.navy.mil which are working OK. 4. Make sure you dont have any deny rule. 5. I'm using that configuration through two ISA servers in a back to back DMZ and it's really working, believe me. Cristian Bratu