Well, the event log is telling me that it's dropping the connection due to user defined black list... so yeah, pretty sure. 🙂
I don't think there is anyway to fix this. IPS, URL filters and the like seem to apply to all traffic in all directions. I wish we could control these in the firewall policy. I guess it's a feature request.