OK, If any of you have previously seen I asked about documentation for a new server, well I just imported the configuration from the old ISA box and created an entirely new ISA2004 SP2 box with a different name and all is working fine apart from a very weird problem. I have a number of VPN users and for the most VPN works correctly and all is as it used to be apart from one of them. When the guy connects to the ISA box he connects without a problem although everyone on the internal side of ISA lose connectivity, you cannot ping the ISA's internal network card. When the VPN client disconnects, everything comes back to normal???? Configuration is as follows: ISA 2004 SP2 SE 2 network cards - 1x External, 1x Internal Fixed IP addresses for internal & external DNS setup on internal network card (pointing to internal DNS server) WINS setup on internal network card (pointing to internal WINS server) Firewall rule for VPN clients to have all outbound protocols go to internal network RRAS setup to pull DHCP range from internal network card Any more info needed just let me know Paul Crisp Snr Network Support Analyst