Hi Brian,
now the block is working; nothing was changed.
from my understanding the sep firewall will check the packets being sent and then see the dns name and block it?
is it possible sep is being overloaded or the severity is not on the right rating?