how I can block for specific internal addresses, specific websites?
sorry for my english ...
This thread was automatically locked due to age.
Internal (Network) -> {service} -> Any : Allow
Internal (Network) -> {service} -> Any : Allow
The second picture shows that you now are using the HTTP/S Proxy in "Transparent" mode. Just change the deifinition of the "Websurfing" group as I said above, and make the changes recommended in post #4 above.
You also should change packet filter rules 1. and 2. from 'Any -> {service} -> Any' toInternal (Network) -> {service} -> Any : Allow
just like the rest of the rules. Since the Astaro is a "stateful" firewall, it keeps track of what it sends so that it can accept the responses without any manual firewall rules.
Cheers - Bob