Is all filtering based off of the web filter? I haven't really looked at it this deeply but since ISA can check HTTPS OWA connections to make sure they're all formed correctly, there is some kind filtering going on. Is the web filter responsible for this or is that something else? Any HTTPS publishing rule essentially terminates the TCP connection at the ISA server, yes? The traffic is then decrypted, examined, and then passed on its way, either over HTTP or HTTPS as dictated by the bridging configuration (terminology is probably messed up). Sorry about the silly questions. :( Cordially yours, Jerry G. Young II Application Engineer Platform Engineering and Architecture NTT America, an NTT Communications Company 22451 Shaw Rd. Sterling, VA 20166 Office: 571-434-1319 Fax: 703-333-6749 Email: g.young@xxxxxxxx -----Original Message----- From: isapros-bounce@xxxxxxxxxxxxx [mailto:isapros-bounce@xxxxxxxxxxxxx] On Behalf Of Thor (Hammer of God) Sent: Wednesday, June 20, 2007 5:05 PM To: isapros@xxxxxxxxxxxxx Subject: [isapros] Fw: Re: Web Filter with HTTPS OK, so you are saying that if I unbind the Web Filter from HTTPS, and create a pub rule for HTTPS, then the filter will still be used for the Pub rule? t -----Original Message----- From: isapros-bounce@xxxxxxxxxxxxx [mailto:isapros-bounce@xxxxxxxxxxxxx] On Behalf Of Jim Harrison Sent: Wednesday, June 20, 2007 5:43 PM To: isapros@xxxxxxxxxxxxx Subject: [isapros] Re: Web Filter with HTTPS The web filter is the part that expects to watch the HTTP traffic as it flows through ISA. With the exception of web publishing, HTTPS traffic is effectively invisible to ISA and therefore any policies enacted via the web filter (think HTTP Filter, too) cannot be applied and ISA will default to "when in doubt, trash it" mode. -----Original Message----- From: isapros-bounce@xxxxxxxxxxxxx [mailto:isapros-bounce@xxxxxxxxxxxxx] On Behalf Of Thor (Hammer of God) Sent: Wednesday, June 20, 2007 1:15 PM To: isapros@xxxxxxxxxxxxx Subject: [isapros] Web Filter with HTTPS Just a sanity check here... why would all HTTPS traffic fail if the Web Filter was bound to the HTTPS protocol? t All mail to and from this domain is GFI-scanned.