Overview

PortBlocker runs as a Windows service under the local SYSTEM account, so it uses the SYSTEM account's proxy settings (HKEY_USERS\S-1-5-18). Proxy settings deployed to users, such as user Group Policy or HKEY_CURRENT_USER, don't apply to PortBlocker.

Proxy requirements

  • Allow HTTPS on port 443 to your SafeConsole server and to media.datalocker.com (PortBlocker software updates).
  • Exclude your SafeConsole server from TLS/SSL inspection. PortBlocker authenticates with a client certificate (mutual TLS), which a TLS-inspecting proxy can't pass through.
  • Authentication: PortBlocker 3.0 supports HTTP Basic proxy authentication. NTLM, Kerberos, and Digest are not supported.

Proxy methods

Configure one method per computer. If more than one is configured, PortBlocker 3.0 uses them in the order listed.


MethodPortBlocker 2.xPortBlocker 3.0
1. PAC scriptYesYes
2. Static proxyYesYes
3. Auto-detect (WPAD)YesYes
4. WinHTTP proxyNoYes
5. PortBlocker proxy settingYes (no authentication)Yes

Upgrading from PortBlocker 2.x

PortBlocker 3.0 reads the same settings as 2.x, including settings made with the Internet Explorer and PsExec steps from earlier versions of this article. Confirm on a pilot computer before upgrading the rest.

Configure the proxy

Run these in an elevated PowerShell window or as SYSTEM. Replace proxy.example.com:8080 with your proxy.

1. PAC script

$sys = 'Registry::HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings'
Set-ItemProperty $sys -Name AutoConfigURL -Value 'http://proxy.example.com/proxy.pac' -Type String

2. Static proxy

$sys = 'Registry::HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings'
Set-ItemProperty $sys -Name ProxyEnable -Value 1 -Type DWord
Set-ItemProperty $sys -Name ProxyServer -Value 'proxy.example.com:8080' -Type String

3. Auto-detect (WPAD)

$conn = 'Registry::HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections'
$v = (Get-ItemProperty $conn -Name DefaultConnectionSettings).DefaultConnectionSettings
$v[8] = $v[8] -bor 0x08    # on  (use -band 0xF7 to turn it off)
Set-ItemProperty $conn -Name DefaultConnectionSettings -Value $v

Note: If WPAD is on your network but you use method 4 or 5, turn auto-detect off, or PortBlocker will use WPAD instead.

4. WinHTTP proxy (3.0 only)

netsh winhttp set proxy proxy-server="proxy.example.com:8080"
  • This applies to all Windows services on the computer.
  • Don't use netsh winhttp import proxy source=ie. It copies the current user's settings, not SYSTEM's.

5. PortBlocker proxy setting

Applies to PortBlocker only.


With authentication (3.0 only): use the PortBlocker command line, which encrypts the password.

& "C:\Program Files\DataLocker\PortBlocker\PortBlocker.exe" proxy set `
    --server proxy.example.com:8080 --username <user> --password <password>
  • The encrypted password works only on the computer where it was set, so run the command on each computer.
  • Run PortBlocker.exe proxy show to check the setting.

Without authentication (2.x and 3.0): set the registry instead.

$pb = 'HKLM:\SYSTEM\CurrentControlSet\Services\DataLockerPortBlockerService\Proxy'
New-Item -Path $pb -Force | Out-Null
Set-ItemProperty $pb -Name ip   -Value 'proxy.example.com' -Type String
Set-ItemProperty $pb -Name port -Value '8080' -Type String

Important: port must be a string (REG_SZ). PortBlocker ignores it if it's a DWORD.

Deploy and apply

  • Group Policy Preferences: Create the registry values under Computer Configuration > Preferences > Windows Settings > Registry. For SYSTEM's settings, use hive HKEY_USERS and key path S-1-5-18\...
  • Intune, Configuration Manager, or other tools: Run the scripts in the SYSTEM context.

Restart the service

PortBlocker reads proxy settings only at startup. Reboot, or add this to your script. Restart-Service can time out and leave the old settings running.

sc.exe stop DataLockerPortBlockerService
Start-Sleep 15
Get-Process PortBlockerService -ErrorAction SilentlyContinue | Stop-Process -Force
sc.exe start DataLockerPortBlockerService

Verify

On a pilot computer running PortBlocker 3.0, wait two minutes after the restart, then check the service log:

Get-Content C:\Windows\Temp\datalocker_pb_service.log -Tail 200 | Select-String "source=|proxy: |304"
  • Which method is in use: source=IeAutoConfigUrl, IeStaticProxy, or AutoDetect
  • Traffic is going through the proxy: proxy: request routed via proxy
  • Successful check-in: HTTP 304 (not an error)

After rollout, confirm in SafeConsole that endpoints are checking in.

Troubleshooting

  • Browsers work but PortBlocker doesn't. The proxy is set for users only. Set it for SYSTEM.
  • PortBlocker uses the wrong proxy. A higher-priority method is also configured. Auto-detect (WPAD) is a common cause.
  • PortBlocker connects to the proxy but never checks in. The proxy is inspecting TLS traffic. Exclude your SafeConsole server from inspection.
  • The log shows a transport error. Check your proxy's logs. 407 means the credentials were rejected. No requests at all means the proxy address or PAC file is wrong.