% if not Session("protected")=true then Response.Redirect "index1.asp?url=" & Server.URLEncode(Request.ServerVariables("URL")) end if %>