Well, the tracert would time out- that¹s ICMP. From the MF, can you not telnet on 25 to a remote SMTP server? t On 4/20/06 12:36 PM, "Greg Hess" <gmh@xxxxxxxx> spoketh to all: > The MF uses our internal DNS that forward to our ISP, so the name resolution > is there. A traceroute from the MF just times out at the IP of the ISA Server. >> >> >> -----Original Message----- >> From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On >> Behalf Of Thor (Hammer of God) >> Sent: Thursday, April 20, 2006 3:14 PM >> To: isalist@xxxxxxxxxxxxx >> Subject: [isalist] Re: SecureNAT - aww man >> Importance: High >> >> What exactly happens when the MF tries to SMTP out? Where does it resolve >> the host DNS from? >> >> >> On 4/20/06 11:32 AM, "Greg Hess" <gmh@xxxxxxxx> spoketh to all: >> >> >>> Hey, I'm trying to get our mainframe to be able to ftp/smtp out using ISA >>> 2000. I thought I just had to set up a client set and give a protocol rule >>> (and point the MF to the ISA for default gateway) but that is not working. >>> >>> - also - >>> >>> I was trying to set up a rule using the PC accounts in AD to allow my >>> domain controllers to get Internet NTP access, but I don't want to install >>> the proxy client, will this still work (again, if ISA is default gateway). >>> I apologize if these questions are simple, but I'm having a brain lock! >>> >>> g. >>> >> >