In other words, the Layer7 rule is treated differently in MX and MR.
In MR, even if port 80 for Facebook or any other website, for example, is allowed in the L3 rule and blocked in the L7 rule, traffic will be allowed because port 80 is explicitly allowed in the L3 rule.
Were you confused?
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.