Monitoring IPS shows that not all traffic is blocked even there is a rule for that classtype.

I have rule to block classtype: misc-attack
I dont have category for 3coresec in a category list to block it.

Also, here is screenshot that IPS somehow allows some ip addresses from same blocked classtype but block others.

Screenshot 2021-06-10 150955.jpg

Any ideas?