Hello Iain!
I read that you have developed a X-Forwarded-For Log Filter for ISA that was successfully tested by Skeep. I would be grateful if you could send me, too, this filter and the instructions how to set it. I had to make a cross upgrade to Trend Micro InterScan Web Security Virtual Appliance which can add the XFF HTTP header. So now I have a chain of proxies. Unfortunately ISA is not able to get from it the originating IP address and the product from Winfrasoft costs too much for me. Thanks a lot.
All the best,
cic