agree , it really doesn't make much sense , please report this to your meraki reps so they fix in future releases. in the meantime , i will try to allow 53 / tcp for dns requests. before the deny all / allowed fqdns for layer3 rule in a group policy, to see if that helps. 
						
					
					... View more