Hello, thanks Steve for your notes but doing exactly what you put I can not browse any site even for those that are within dst_allowssl.acl.
What I need is that users can surf all sites except as expressly denied.
Doing what you propose is true that connects ultrasurf but I can not browse any website.
Thanks
That logic won't work with Ultrasurf.
Ultrasurf has access to thousands of secure sites and talks to them over port 443.
This list keeps changing and growing every day, keeping this list up to date is impossible.
The logic I used is to ALLOW ONLY TRUSTED SITES to use secure ports.
In your office or school environment this number will be very small. (Paypal, eBay, Banks ...)
If a user wants access to a particular secure site all you have to do is add it to the list of trusted sites.