Well the student is back...still licking my wounds from yesterday. Anyway, thought I had this working yesterday but maybe not. ISA tri-homed with Web server in DMZ. Have created a packet filter on the ISA server with the ISA's external interface and pointed the other end to the Web server. I can telnet from ISA on port 80 to the web server but when I try and do that from outside the public interface the ISA log shows that connection attempt as being blocked. The protocol is predefined as TCP 80 inbound for local and any port for remote. Is there something else I am suppose to do to expose the service on the DMZ? thanks in advance, LA