They can disable the Proxy Settings only if they can get to the settings tab, which you can lock down via GPO. Whether you force the settings in via GPO or FWC, doesn't make any difference at that point. ________________________________ From: Roy Tsao [mailto:roy_tsao@xxxxxxxxxxxx] Sent: Thursday, March 24, 2005 10:34 To: [ISAserver.org Discussion List] Subject: [isalist] RE: possible fix RE: ISAserver.org - Review of SurfControl Web Filter 5.0 for ISA Server 2004 http://www.ISAserver.org in case of FWC, client side can uncheck web proxy by themselves, means they can pass filter via surfcontrol if they can to go to website prohibited by company rule, so I think GPO is necessary!