Mon Jun 12, 2017 11:57 pm
Make sure that the rule comes before any other rule that would accept the packets.
For instance, if there's a rule in the forward chain which accepts all packets when out-interface=WAN, and if this rule comes before (above) your "block SMB" rule, then the block rule is never going to get a chance to match because the firewall stops as soon as it matches a packet. (just drag your block rule higher up the list - (preferably after the "accept connection-state=established,related" rule)