Hi,
Version 6.24 onwards (afaik) whether you delete the firewall rule or disable they keep on working. I’d seen it on many occassions. I had to reboot the router (seen on ccrs).
You probably have the following rule or similar in your config-
/ ip firewall filter add action=accept connection-state=established
this rule is present in all the routers but strangely one ccr 1009 having just one natting rule showed the same problem. I dropped a mac address. After disabling the rule, the mac address which was a mobile device still was blocked. Rebooted the mobile still no browsing, rebooted the ccr and browsing started on mobile.
You’d have to post a full export for better diagnosis