I'm trying to setup a Internet only Policy for wired ports. I've created permit role and added deny destination rules for our local networks. I've also added allow rules for dns, dhcp, etc. It looks like rule precedence is tripping me up as the denys are before the permits so everthing is blocked locally. Is there a way to make rules have different precedence or a diffrent way to do this.
![1d7fb2bb53fd4e88a21a3baf384aed4f_RackMultipart20170911-102927-2q7j6x-snip_20170911135632_inline.png 1d7fb2bb53fd4e88a21a3baf384aed4f_RackMultipart20170911-102927-2q7j6x-snip_20170911135632_inline.png](/t5/image/serverpage/image-id/3977i3786402AEA9C9A85/image-size/large?v=v2&px=999)