Hi, I read that you must be setup as a SecureNAT client to be able to VPN out through the ISA Server. I am setup as a FW client and I am able to VPN out. I do have the SecureNat PPTP Packet Filter enabled. Even with the Filter disabled I am still able to VPN out. I do turn up in the sessions list as both a SecureNAT and a FW session. None of our Protocol and Site and Content rules allow SecureNAT clients out. All are ased on NT Users and Groups. All latest patches have been applied. How can this be happening? TIA Nathan Simpson