create the restricted policy whitelist with the allowed sites, for the blacklist simply add **
this will only allow "http" access to internet sites within the whitelist.
local traffic will not be effected, nor will https, unless your using 3.0, which I have yet to toy with
