When using Client or Mixed Control mode, Endpoint Protection (SEP) clients will block IGMP network traffic with the "Allow IGMP traffic" user defined firewall rule.
Firewall traffic logs show:
Timestamp Severity Action Protocol Remote Hostname Remote IP Remote Port Local IP Local Port Application Direction Start Time End Time Count Alert Rule
6/27/2019 3:42:39 PM 3 Blocked IP 172.12.255.100 0 224.0.0.22 2 Incoming 6/27/2019 3:42:13 PM 6/27/2019 3:42:25 PM 5 No Allow IGMP traffic
Pic from UI:
{KNOWN_ISSUE.EN_US}
As a workaround, you can edit the "Allow IGMP traffic" rule to block the traffic and then set it back to allow and the rule should work properly.