You still have to allow tcp port 3128