It seems I can only use my protocol rules for smtp, pop3, msn messenger, etc. through my ISA server if I install the firewall client. If I just make my wrkstn a secure NAT client (which means the wrkstn uses the ISA server as its default gateway right?) all I can do is HTTP. I was under the impression either method would yield the ability to run traffic through the ISA server if you allowed it with a protocol rule. Thoughts? Tia