The MF uses our internal DNS that forward to our ISP, so the name resolution is there. A traceroute from the MF just times out at the IP of the ISA Server. -----Original Message----- From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of Thor (Hammer of God) Sent: Thursday, April 20, 2006 3:14 PM To: isalist@xxxxxxxxxxxxx Subject: [isalist] Re: SecureNAT - aww man Importance: High What exactly happens when the MF tries to SMTP out? Where does it resolve the host DNS from? On 4/20/06 11:32 AM, "Greg Hess" <gmh@xxxxxxxx> spoketh to all: Hey, I'm trying to get our mainframe to be able to ftp/smtp out using ISA 2000. I thought I just had to set up a client set and give a protocol rule (and point the MF to the ISA for default gateway) but that is not working. - also - I was trying to set up a rule using the PC accounts in AD to allow my domain controllers to get Internet NTP access, but I don't want to install the proxy client, will this still work (again, if ISA is default gateway). I apologize if these questions are simple, but I'm having a brain lock! g.