<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Blocking 443]]></title><description><![CDATA[<p dir="auto">I have one computer on x.x.x.125 (static) that I would like to block port 443. I had set up the rule below:</p>
<p dir="auto">Action: block<br />
Interface: LAN<br />
Source: x.x.x.125<br />
Destination port: 443 to 443</p>
<p dir="auto">It's listed above the default rules (except the anti lockout rule)</p>
<p dir="auto">When I turn the rule on, it blocks all traffic from x.x.x.125 instead of just port 443.</p>
<p dir="auto">Could someone give me a hint on what I may have set incorrectly?</p>
<p dir="auto">(Backstory in case anyone is interested: I have dansguardian with squid up, but the users on this system are using https proxy sites to bypass the filter.)</p>
]]></description><link>https://forum.netgate.com/topic/92446/blocking-443</link><generator>RSS for Node</generator><lastBuildDate>Mon, 20 Apr 2026 21:43:06 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/92446.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 01 Dec 2015 19:23:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 23:48:04 GMT]]></title><description><![CDATA[<p dir="auto">Yea… This is temporary until e2guardian is ready to use with Pfsense. But seems that on hold until the next major release.</p>
]]></description><link>https://forum.netgate.com/post/588054</link><guid isPermaLink="true">https://forum.netgate.com/post/588054</guid><dc:creator><![CDATA[Samuel_R]]></dc:creator><pubDate>Tue, 01 Dec 2015 23:48:04 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 23:32:46 GMT]]></title><description><![CDATA[<p dir="auto">you do know proxies run on lots of different ports not just 80 or 443..</p>
]]></description><link>https://forum.netgate.com/post/588053</link><guid isPermaLink="true">https://forum.netgate.com/post/588053</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 01 Dec 2015 23:32:46 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 22:56:38 GMT]]></title><description><![CDATA[<p dir="auto">For port 80, I used bbc.com to validate the Internet still works with the block. As to blocking individual sites, there are just too many, and new ones are created every day.</p>
<p dir="auto">I can see http site logs through light squid to see what is being accessed, but short of putting in a man in the middle, I'm not sure how I could see what https sites are being accessed… Yes, I'm still fairly new to this.</p>
<p dir="auto">These are teenaged kids using this computer "for homework", and our view is to block everything and release as needed, since they keep using it for inappropriate sites and we can't be within viewing range 24/7.</p>
]]></description><link>https://forum.netgate.com/post/588048</link><guid isPermaLink="true">https://forum.netgate.com/post/588048</guid><dc:creator><![CDATA[Samuel_R]]></dc:creator><pubDate>Tue, 01 Dec 2015 22:56:38 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 21:26:32 GMT]]></title><description><![CDATA[<p dir="auto">what exactly where you testing too on 80, so is it still not working or was it your router hiccup when you were at machine?  As stated there are many sites that redirect to 443 now a days.  So could of been one of those..  I just checked and unless its my browser with a cache something even www.pfsense.org redirects to 443.</p>
<p dir="auto">Blocking 443 is going to break a lot of internet for this IP..  Prob better to try and block the proxies he is using with a list?  Its an uphill battle to be sure</p>
]]></description><link>https://forum.netgate.com/post/588024</link><guid isPermaLink="true">https://forum.netgate.com/post/588024</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 01 Dec 2015 21:26:32 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 21:19:54 GMT]]></title><description><![CDATA[<p dir="auto">It could also perhaps be a server that redirects to 443 from 80.</p>
]]></description><link>https://forum.netgate.com/post/588021</link><guid isPermaLink="true">https://forum.netgate.com/post/588021</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Tue, 01 Dec 2015 21:19:54 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 21:05:11 GMT]]></title><description><![CDATA[<p dir="auto">Final need, how would I go about allowing the user to get to Google.com (requires https) I know that they have quite a few ip addresses, is there an updated list for all of googles ip addresses. (Both for .com and .com.ua as I live in Ukraine).</p>
<p dir="auto">As to the Internet not being available, seems our router hiccuped at the time of the visit to the machine. ;)</p>
]]></description><link>https://forum.netgate.com/post/588019</link><guid isPermaLink="true">https://forum.netgate.com/post/588019</guid><dc:creator><![CDATA[Samuel_R]]></dc:creator><pubDate>Tue, 01 Dec 2015 21:05:11 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 20:38:44 GMT]]></title><description><![CDATA[<p dir="auto">Heh. Yea, except I came and visited the computer and couldn't access via port a<br />
80 either. Strange. At least I know the rule is correct. I'll chase down other possibilities. Thanks for taking a look!</p>
]]></description><link>https://forum.netgate.com/post/588011</link><guid isPermaLink="true">https://forum.netgate.com/post/588011</guid><dc:creator><![CDATA[Samuel_R]]></dc:creator><pubDate>Tue, 01 Dec 2015 20:38:44 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 20:34:33 GMT]]></title><description><![CDATA[<p dir="auto">Well that looks correct.. It would only fire on traffic going to 443 udp and tcp.. If traffic was to anything else it would fall through and your any any rule would fire.</p>
<p dir="auto">Sure is internet is broke because he is using a proxy over 443 and you blocked that ;)</p>
]]></description><link>https://forum.netgate.com/post/588007</link><guid isPermaLink="true">https://forum.netgate.com/post/588007</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 01 Dec 2015 20:34:33 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 20:16:42 GMT]]></title><description><![CDATA[<p dir="auto">Here are the rules. The rule is currently disabled to allow internet access on the computer</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/image.png" alt="image.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/image.png_thumb" alt="image.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/587996</link><guid isPermaLink="true">https://forum.netgate.com/post/587996</guid><dc:creator><![CDATA[Samuel_R]]></dc:creator><pubDate>Tue, 01 Dec 2015 20:16:42 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 20:04:21 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">I'll have to find a host for an image.</p>
</blockquote>
<p dir="auto">You can post images directly to the forum.</p>
]]></description><link>https://forum.netgate.com/post/587985</link><guid isPermaLink="true">https://forum.netgate.com/post/587985</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Tue, 01 Dec 2015 20:04:21 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 19:41:09 GMT]]></title><description><![CDATA[<p dir="auto">I'll have to find a host for an image.</p>
<p dir="auto">As to the x.x.x, I'm just used to it for documentation. Been writing lots of documentation. The full address is 10.102.1.125.</p>
]]></description><link>https://forum.netgate.com/post/587973</link><guid isPermaLink="true">https://forum.netgate.com/post/587973</guid><dc:creator><![CDATA[Samuel_R]]></dc:creator><pubDate>Tue, 01 Dec 2015 19:41:09 GMT</pubDate></item><item><title><![CDATA[Reply to Blocking 443 on Tue, 01 Dec 2015 19:29:21 GMT]]></title><description><![CDATA[<p dir="auto">can you post a screenshot of your rules..</p>
<p dir="auto">Are you using public IPs.. why the x.x.x if the address is rfc1918??</p>
]]></description><link>https://forum.netgate.com/post/587967</link><guid isPermaLink="true">https://forum.netgate.com/post/587967</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Tue, 01 Dec 2015 19:29:21 GMT</pubDate></item></channel></rss>