
It's in the #1 position but when I test, it's not blocking traffic.
I have one computer with an external Internet connection that I'm using for testing. I included it's public IP in the block list but I can still access my websites that are hosted on a server that's behind Sophos.
Each website has a DNAT and a Full NAT (for local access). Each DNAT and Full NAT has an automatic packet filter rule.
One of the DNAT's:

The corresponding Full NAT:

Why is this rule not blocking my testing computer?
This thread was automatically locked due to age.