I agree with @ww, the firewall rule is based on flow hence wait a 5-10 minutes after the rule is applied so that the preexisting flow expires and new ones from the client get processed by the firewall. Also, ensure the configs are up to date on the Security & SD-WAN > Appliance status page after the rule was added.
If you are exporting your flow logs to a syslog server you should see it matching when the new config takes. Normally you should see a flow_end matching your existing flow and after that the rule should take.