Can you define "a lot"? My idea might be 40, where your idea of a lot of signatures is 20, for example.
I know it's getting applied - here's how I tested:
I had a subgroup, and moved all clients to the subgroup. I went into the signature, and unchecked one of the sigs I added yesterday. I then removed inheritance, and found the clients now were blocked from certain sites. The parent group I put myself in, and I was not blocked. When I unchecked another sig I added yesterday, then it started working, when i checked it again, it stopped working.
Weird, I thought that inheritance wouldn't apply to the custom IPS, but it seems to have impact somehow.
I checked the format of the recently added signatures...
These are examples so others can proof my work:
rule tcp, dest=(80), msg="IBIBO online games Website",content="ibibo.com"
rule tcp, dest=(80), msg=kvik radio streaming",content="kvikradio.com/streaming"
rule tcp, dest=(80), msg="MySpace music",content="myspacecdn.com"
rule tcp, dest=(80), msg="generic flash radio",content="flash/radio"
WAIT - I think I see it - Could the lack of a " be the issue?? Check the second one down, that's the one I added about the time it "broke". It wasn't until I pasted them here, one right above the other, no spaces, that I noted one seemed to be "shorter" than the others..
Anyway, use of radio streaming and other "junk" has become SO prevalant here, I've had to "do something" about it, and came up with a list of ways that WMP and other things like FLASH stream radio without blocking port 80 for everyone. There's a multitude of sites and players, but as I find 'em, I block them.
I may have just solved the mystery thanks to some prompting.