Content filter whitelist won't work since it is getting blocked by the Layer 7 firewall and not the content filtering.
I'm not sure the Layer 3 allow would work either but I'll test it and report back. Yes we have Advanced Security license. Here is what the documentation says.
On the MX, HTTP traffic (TCP port 80) to Facebook.com will be blocked by the L7 firewall, because rule 1 under layer 7 explicitly blocks it, even though the traffic was allowed through the layer 3 firewall.
Layer 3 Rules
Matched - Traffic allowed through L3 firewall
Not processed
Not processed
Layer 7 Rules
Matched - Traffic blocked
Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.