What I want:

Access Rule that blocks ALL attempts to download in a browser any file that ends with a specific extension (.exe for example).

What I have:

Access Rule:

Type: Port
Source DNS Hostname: Any
Destination DNS Hostname: *.exe
Origin Server Port: 1-65535
Action: Deny Access

What is happening:

I apply the rule and test and I am denied the first attempt.
When another attempt is made, the action is allowed.

Monitor shows the following error message when rules changes are applied:

Unable to read configuration from NDS (error - -672)

Note: I just removed ALL rules listed in iManager, saved and I am still able to access web pages. I though that by default access is denied?