Hi all, No need to get excited; this is going out to every ISA-related list I'm on. When you have a question about why your rules behave "this way", at the very least, you need to provide: - Details of the rule in question (can copy this straight from the ISAInfo display) - Details of the Network Rule(s) that apply to the source and destination network objects - ISA logging excerpts related to this traffic It's nearly impossible to evaluate ISA rule behavior without this minimal data. Ideally, you'd be able to provide the whole ISABPA/ISAInfo/Log, but many lists block attachments. ------------------------------------------------------- Jim Harrison MCP(NT4, W2K), A+, Network+, PCG http://isaserver.org/Jim_Harrison/ http://isatools.org Read the help / books / articles! ------------------------------------------------------- All mail to and from this domain is GFI-scanned.