Overview
PortBlocker runs as a Windows service under the local SYSTEM account, so it uses the SYSTEM account's proxy settings (HKEY_USERS\S-1-5-18). Proxy settings deployed to users, such as user Group Policy or HKEY_CURRENT_USER, don't apply to PortBlocker.
Proxy requirements
- Allow HTTPS on port 443 to your SafeConsole server and to
media.datalocker.com(PortBlocker software updates). - Exclude your SafeConsole server from TLS/SSL inspection. PortBlocker authenticates with a client certificate (mutual TLS), which a TLS-inspecting proxy can't pass through.
- Authentication: PortBlocker 3.0 supports HTTP Basic proxy authentication. NTLM, Kerberos, and Digest are not supported.
Proxy methods
Configure one method per computer. If more than one is configured, PortBlocker 3.0 uses them in the order listed.
| Method | PortBlocker 2.x | PortBlocker 3.0 |
|---|---|---|
| 1. PAC script | Yes | Yes |
| 2. Static proxy | Yes | Yes |
| 3. Auto-detect (WPAD) | Yes | Yes |
| 4. WinHTTP proxy | No | Yes |
| 5. PortBlocker proxy setting | Yes (no authentication) | Yes |
Upgrading from PortBlocker 2.x
PortBlocker 3.0 reads the same settings as 2.x, including settings made with the Internet Explorer and PsExec steps from earlier versions of this article. Confirm on a pilot computer before upgrading the rest.
Configure the proxy
Run these in an elevated PowerShell window or as SYSTEM. Replace proxy.example.com:8080 with your proxy.
1. PAC script
$sys = 'Registry::HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings' Set-ItemProperty $sys -Name AutoConfigURL -Value 'http://proxy.example.com/proxy.pac' -Type String
2. Static proxy
$sys = 'Registry::HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings' Set-ItemProperty $sys -Name ProxyEnable -Value 1 -Type DWord Set-ItemProperty $sys -Name ProxyServer -Value 'proxy.example.com:8080' -Type String
3. Auto-detect (WPAD)
$conn = 'Registry::HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections' $v = (Get-ItemProperty $conn -Name DefaultConnectionSettings).DefaultConnectionSettings $v[8] = $v[8] -bor 0x08 # on (use -band 0xF7 to turn it off) Set-ItemProperty $conn -Name DefaultConnectionSettings -Value $v
Note: If WPAD is on your network but you use method 4 or 5, turn auto-detect off, or PortBlocker will use WPAD instead.
4. WinHTTP proxy (3.0 only)
netsh winhttp set proxy proxy-server="proxy.example.com:8080"
- This applies to all Windows services on the computer.
- Don't use
netsh winhttp import proxy source=ie. It copies the current user's settings, not SYSTEM's.
5. PortBlocker proxy setting
Applies to PortBlocker only.
With authentication (3.0 only): use the PortBlocker command line, which encrypts the password.
& "C:\Program Files\DataLocker\PortBlocker\PortBlocker.exe" proxy set `
--server proxy.example.com:8080 --username <user> --password <password>- The encrypted password works only on the computer where it was set, so run the command on each computer.
- Run
PortBlocker.exe proxy showto check the setting.
Without authentication (2.x and 3.0): set the registry instead.
$pb = 'HKLM:\SYSTEM\CurrentControlSet\Services\DataLockerPortBlockerService\Proxy' New-Item -Path $pb -Force | Out-Null Set-ItemProperty $pb -Name ip -Value 'proxy.example.com' -Type String Set-ItemProperty $pb -Name port -Value '8080' -Type String
Important: port must be a string (REG_SZ). PortBlocker ignores it if it's a DWORD.
Deploy and apply
- Group Policy Preferences: Create the registry values under Computer Configuration > Preferences > Windows Settings > Registry. For SYSTEM's settings, use hive
HKEY_USERSand key pathS-1-5-18\... - Intune, Configuration Manager, or other tools: Run the scripts in the SYSTEM context.
Restart the service
PortBlocker reads proxy settings only at startup. Reboot, or add this to your script. Restart-Service can time out and leave the old settings running.
sc.exe stop DataLockerPortBlockerService Start-Sleep 15 Get-Process PortBlockerService -ErrorAction SilentlyContinue | Stop-Process -Force sc.exe start DataLockerPortBlockerService
Verify
On a pilot computer running PortBlocker 3.0, wait two minutes after the restart, then check the service log:
Get-Content C:\Windows\Temp\datalocker_pb_service.log -Tail 200 | Select-String "source=|proxy: |304"
- Which method is in use:
source=IeAutoConfigUrl,IeStaticProxy, orAutoDetect - Traffic is going through the proxy:
proxy: request routed via proxy - Successful check-in: HTTP
304(not an error)
After rollout, confirm in SafeConsole that endpoints are checking in.
Troubleshooting
- Browsers work but PortBlocker doesn't. The proxy is set for users only. Set it for SYSTEM.
- PortBlocker uses the wrong proxy. A higher-priority method is also configured. Auto-detect (WPAD) is a common cause.
- PortBlocker connects to the proxy but never checks in. The proxy is inspecting TLS traffic. Exclude your SafeConsole server from inspection.
- The log shows a transport error. Check your proxy's logs.
407means the credentials were rejected. No requests at all means the proxy address or PAC file is wrong.