The class of audit log shows as TERMINAL for outgoing network access instead of CONNECT/TCP.
If seosd.bypass_xdm_ports token in seos.ini is yes (default value), the access for port #6000 - 6010 on outgoing network connection is controlled as TERMINAL class instead of network class (CONNECT/TCP) and the class in audit log is also TERMINAL instead of CONNECT/TCP.
You can change bypass_xdm_ports to no. It makes the access to above ports is treated as network class same as other ports. You can bypass such access by creating specialpgm of accessed program with xdm pgmtype.