Trying to expose WEB,DNS and SMTP on a tri-homed ISA in the DMZ. I have created packet filters for all three. I have packet filtering and ip forwarding enabled on the packet filter properties. The filters have the external interface of the ISA and the corresponding interface of the PC in the DMZ. I can verify the service from ISA to the DMZ by telnetting to port 80 for example and get a connection. This does not work from outside the external interface of the ISA server. The log shows the outside connection attempt being blocked???? The filter is set for 'any' outside connection. I have shutdown the box down and restarted with the same results. What have I missed? Any comments would be appreciated. thanks, LA