Thanks to SnDPhoenix:
By adding to your ini file:
ClosedFilePath=!firefox.exe,\Device\Afd* ClosedFilePath=!firefox.exe,\Device\Tcp ClosedFilePath=!firefox.exe,\Device\Udp ClosedFilePath=!firefox.exe,\Device\RawIpYou can block internet access for all programs sandboxed except for Firefox, (of course you could replace firefox with whatever the name of your browsers executable is e.g Opera.exe, Iexplore.exe, etc..)
If you decide to add the above lines don't forget to hit the "Reload Configuration" button.
Then you may want to try some of the leaktests from a sandboxed browser at the link below.
Firewall leak tester













