Yes, dealing without going is something of a mess. Here is the approach I am using with pretty good success so far. As, I recall, my approach is the "opposite" of yours.
1. Block all outgoing not allowed by a rule (mine or Vista's) with notification. I am yet to receive any "natural" notifications, although I can create the one snipped below.
2. Allow Firefox by rule.
3. Block LeakTest with specific rule. I could not prevent LeakTest from reaching the Web otherwise, and I received no notification it was attempting to do so. |