Sorry for delay. Low pH?
I saw in your pics you was using any | any | any | any.
In my mind, if traffic will reach clients behind zywall, and will come back to internet (or is your Device filtering Public IPs without have lan/client hosts involved?), in firewall rules you need to set something like this
From LAN to WAN source=WHATEVERYOULIKE dest=YOUTUBEX deny/reject and/or Services/Ports=Youtube-Services/Ports or what you like.
Just this, no more than to notify device the zone-pair where rule should be applied.
I saw that subsequent pics had this setting.
Sorry to have bored you.