Works for me - bridge@EWC, V10.21.02, AP3705i, in my case I've blocked traffic as that was easier to test.
Note: it took some minutes before the traffic was blocked so I'm not sure whether I've done something wrong or whether there is some sync happening until it's active.
![59274111038a4d738c97d92a1d5bfb87_RackMultipart20170227-104265-14ajfxa-EWC_L7_inline.png 59274111038a4d738c97d92a1d5bfb87_RackMultipart20170227-104265-14ajfxa-EWC_L7_inline.png](/t5/image/serverpage/image-id/4809i5A8F33FB8F19DBF9/image-size/large?v=v2&px=999)
Have you enabled application visibility on the WLAN service ?
Back to the overall goal...I'm not sure whether I unterstand the setup..
the WLAN service is set to authentication for external captive portal and the screenshot show the unauthenticated traffic role ?
And then in case someone uses facebook, mail it should redirect to the portal and the user needs to authenticate on the portal ?