What did i wrong? To overcome the problem i defined 3 "all allow" rules (!!!!), a protocol-, a content- and a packet rule! Everything else is working fine now. But from client PCs i can connect to the ftp server, but typing "ls" or "dir" leads to an "invalid port command"-message. From the isa-Server itself it works! Its all open (during test phase) What else can i check out?? Thanx for Info!