Doing it with packet filter rules certainly works: 'Internal (Network) -> [80,443] -> [203.206.0.0/16]'.
I only made the HTTP/S suggestion because I was looking for more input on an overall theory for implementing Web Security. My current thinking is that the base/default always should be in transparent mode, and that it should include the strictest limitations. I don't feel like I've tested that idea enough though.
Doing it with packet filter rules certainly works: 'Internal (Network) -> [80,443] -> [203.206.0.0/16]'.
I only made the HTTP/S suggestion because I was looking for more input on an overall theory for implementing Web Security. My current thinking is that the base/default always should be in transparent mode, and that it should include the strictest limitations. I don't feel like I've tested that idea enough though.