Hy Glenn [cut] > Aside from a few ports (SMTP, POP3, IMAP, DNS, etc. on the > DMZ), the LAN won't be able to go anywhere. Except for me, of > course; I can go anywhere... > > > Don't know if this is going to work, but if it does, rules > similar to these may solve your problem. With no proxy whinage. This *is* going to work, I did such setups too, some years ago. The fact is, that similar solutions require some more intervention, because (as you might know) every day a new software/tool/internet application needs to be used (and it is FOR SURE that it HAS to be used, for working purposes, not for joke)... This would mean, adding rules from time to time... Good luck, but still I confess that I *may be* switching to this your suggestion too! ;-) Flavio Boniforti PIRAMIDE INFORMATICA SAGL Via Ballerini 21 6600 Locarno Switzerland Phone: +41 91 751 68 81 Fax: +41 91 751 69 14 URL: http://www.piramide.ch E-mail: flavio@xxxxxxxxxxx