A good point - while DHCP discovery is sent to the broadcast address, DHCP renews are sent to the individual address of the DHCP server which would be blocked along with the subnet. So an exception from the subnet-blocking rule forI think you will need to allow the communication to the DHCP server first
protocol=udp src-port=68 dst-port=67