I have users that are bypassing ISA 2004 w/ surfcontrol security. The way it is happing is they are having the workstations resolve the internal addresses to the ISA server address and then firing the URL to ISA. Surfcontrol is looking at the raw ip address and bypassing the filter check. What would be allowing the Windows 2000 users with IE6 to trick ISA. The users who are successfully blocked have the destination IP addresses show up as untranslated like “www.foobar.com”