Try by making it as server control
For this
Login to SEPM
Clients----------> <prefered group>--------->policies (right side) ------>client user interface control settings ( under location specific settings)---------->select server control and give ok
In the firewall policies keep the policy which you created as first policy.
If you want to get logs in the client write to traffic log /write to packet log should be selected .This you can do by right clicking on that rule in logging column..