Specifying src MAC or IP prevents filter rule from working

Hi,

I’ve been trying different configurations for hours and can’t get this to work.

It is a simple filter rule: It is enabled, it is on the forward chain, it uses a layer 7 Regexp to reject Facebook.com and youtube.com. If that is all I specify in the filter rule it works fine and rejects from all LAN clients. If I add a src IP address or a src MAC address it no longer blocks Facebook or Youtube from anyone on the LAN and not from the specified address. If I specify the IP address as a dst address it rejects for the specified address.

What am I missing here, or am I looking at the src and dst rules incorrectly?

Thanks