Ok, I have ISA server 2000, I have had is set up through DHCP to point everyone's gateway to "MAPROXY"'s address thus allowing everyone access to the internet. I have changed the gateway in or DNS to the .1 address of our internal router, this has removed access to all but the Firewall Client users and those that have the IE Proxy information set in IE. Does that sound correct? Next I need to disallow the IE web proxy access, how? And when I add a rule to allow only a AD group to have access through the ISA server tends to no allow anyone. I have Mr. Shinder's book, but am having problems finding answers to the questions I have due to lack of experience. ( I admit I am lacking on this subject big time ) Thanks for any help .. ;) -j Jack Spradling Michael Angelo's Gourmet Foods Austin, TX 512-218-3636 (direct line) jack@xxxxxxxxxxxxxxxxxx