If any traffic doesn't match the previous rules, it will get caught by this rule and action taken.
Not sure, do you have different policies applied? Do you have some sort of other filtering in palce? Are these machines configured with a static DNS of 8.8.8.8. I assume you don't want them using google DNS?
ICMP type 3 code 3 means destination unreachable so they can't talk to 8.8.8.8
Ideally they should be configured to use your internal DNS server not google.