It should block if in protect mode, there are few exceptions for a couple of CNIs. For example, protect mode for cilium is not currently supported (it will be shortly).
quiet-fountain-46593
11/04/2022, 11:36 PM
there’s also a way to set the network mode globally, and the individual modes per group only apply to process protection. But there is a large banner in the UI that will say something like, “Global network policy is set to: Monitor” this is not turned on by default