In the environment user create web server on port 80 & 443. Need to create a Endpoint Protection (SEP) firewall policy to restrict http(80) & https(443) inbound port.
SEP 14.3.x
Working as design.
Traffic via browser and curl to the web server goes through the loopback adapter.
SEP firewall does not block traffic on the loopback adapter by design.