As an alternative, I disabled all these settings and implemented "8.2.7. HTTP Authentication" of "NetDefendOS_2.26_Firewall_UserManual_v1.10.pdf" which I just downloaded.
I now get asked for a username and password, but once entered get told:
Logged on
You, or someone else from your IP address,
have been granted access.
Click here to log out.
It never moves on to the web page I was trying to access.
Were I to get this working, will it cause grief with windows updates, and if so is it possible to tweak it so that it doesn't?
The settings I added were:
(My LAN is 192.168.54.*)
AddressBook:
HTTPAllowed 192.168.54.0/24 WebUsers
I added Rules->IP rules:
9 allow_httpProxy Allow lan lannet core lan_ip http-all
10 allow_httpProxy Allow lan lannet core lan_ip http-all
11 allow_httpProxy NAT lan HTTPAllowed wan all-nets http-all
12 allow_httpProxy NAT lan lannet wan all-nets dns-all
13 allow_httpProxy SAT lan lannet wan all-nets http-all
14 allow_httpProxy Allow lan lannet wan all-nets http-all
15 http2fw Allow lan lannet core lan_ip http
Existing rules higher than these were (just in case any of these are causing grief):
1 OpenVPN_LAN
1 OpenVPN_allow FwdFast lan all-nets lan all-nets all_services
2-5 disabled
6 OpenVPN_allow Allow any lannet any OpenVPNNet all_services
7 OpenVPN_allow Allow any OpenVPNNet any lannet all_services
2 OpenVPN_SAT SAT any all-nets core wan_ip OpenVPN
3 OpenVPN_NAT NAT any all-nets core wan_ip OpenVPN
4 SAT_DNS_Relay SAT lan lannet core lan_ip dns-all
5 Allow_DNS_Relay NAT lan lannet core lan_ip dns-all
6 OpenVPN_allow Allow any all-nets core wan_ip OpenVPN
7 SMTP_allow Allow any all-nets lan lannet smtp
8-12 disabled
13 lan_to_wan
1-3 disabled
4 drop_smb-all Drop lan lannet wan all-nets smb-all
5 allow_ping-outbound NAT lan lannet wan all-nets ping-outbound
6 allow_ftp-passthrough NAT lan lannet wan all-nets ftp-passthrough
7-8 disabled
new rules - see above
16 allow_httpProxy NAT lan lannet any all-nets http
Local User Database:
WebUsers
And in WebUsers I added a username and password (no group - do I need to specify a group?).