If you are adding config via the CLI you have a hybrid/monitored switch. If traffic is not actually being blocked this is likely some sort of data/gui bug with how the dashboard is reading your CLI config. I'd open a support case. If traffic is actually being blocked you may want to consult the regular community.cisco.com or regular TAC to look at your config, while many of us are familiar with both modes of deployment there are many more folks familiar over there.
					
				
			
			
				
	If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.