I am sure someone could try to find a way - BUT if you are using Secure ICA into the DMZ and Nfuse / CSG are tied down as per the Citrix Best Practices, add the STA server on the back end of the DMZ - I think the chances are remote. Of course nothing will be in a domain. Now if you want to be really nasty - add something like a SecureID token ********************************************** This weeks sponsor 99Point9.com 99Point9 helps solve your unresolved technical server-based questions, issues and incidents. http://www.99point9.com *********************************************** For Archives, to Unsubscribe, Subscribe or set Digest or Vacation mode use the below link. http://thethin.net/citrixlist.cfm