>Incidentally, I cannot get e-trust inoculate IT 6 on the server that ISA is installed on to download it's auto-dat updates using ftp. I have had to download them manually and then install them. Rich I set this up the other day but didn't note the settings down - just make sure packet logging in turned on then force an update then look at log to see what's getting blocked. From memory I made TWO seperate packet filters one for outgoing and one for incoming ftp and specified the class B subnet that Inoculate connects to (think it was 163...) I would have liked to make it tighter but different IP #'s within this subnet are used each time a download is attempted - perhaps there may only be several but I didn't have time to work this out via trial and error. In fact it would've been nice if CA had the EXACT FW packet filter setting available but when I called their support line it was embarassingly clear (for CA) that I was wasting my time trying to get that 'level' of info from there. Nigel TechBase