When using Client or Mixed Control mode, Endpoint Protection (SEP) clients will block IGMP network traffic with the "Allow IGMP traffic" user defined firewall rule.
Firewall traffic logs show:
Timestamp Severity Action Protocol Remote Hostname Remote IP Remote Port Local IP Local Port Application Direction Start Time End Time Count Alert Rule
6/27/2019 3:42:39 PM 3 Blocked IP 184.108.40.206 0 220.127.116.11 2 Incoming 6/27/2019 3:42:13 PM 6/27/2019 3:42:25 PM 5 No Allow IGMP traffic
Pic from UI:
As a workaround, you can edit the "Allow IGMP traffic" rule to block the traffic and then set it back to allow and the rule should work properly.