Does every application rule need "ask" at the bottom now?

Even if there is an “Allow” in the application rules, it still has to go past the global rules, however if there’s no block or allow rule for the traffic in question then global rules is considered not answering it and then it’s allowed out because application rules says it’s allowed.

So if You have an “Allow” application rule then for global rules “Allow” means to allow it “Block” means to block it anyway and no rule means it doesn’t care and the application rules can do whatever.

So personally I remove all “Allow all” rules from the global rules since they’re basically useless and sort of ruins the security.

For a more in-depth explanation of how the outgoing rules work you may take a look at this quote