Remember that Symantec Endpoint Protection will have to process every packet against your entire list for ALL traffic to see if it passes your rule.
While this is not a huge workload for a dedicated firewall or proxy server, you may clobber the performance of your desktops or laptops.
This is better off getting implemented on a gateway device.
Ray