Hi OC, the easy answer is to email the company, as they know a lot more than me. One of these days I have to go and do that! About the leak test, do not get to worried about it. What it is designed to do, is pretend to be a Trojan program that fools a software firewall. I don't think a hardware firewall can block a Trojan program, thats why you need a software firewall also. The test you need to check is the shieldsup test. First some back ground. your computer, connects to your router which connects to your broadband connection (DSL/Cable) modem. I take it you would like to get a reading of Stealth, and not Closed for all ports. What you really don't want is for them to say open! Open means your connection said come on in. Closed means your connection said I am here but I am not opening the door. Stealth means your connection did not say anything , or open the door, no one knows if you are home or not. Now for some bad news, in the old days of dialup, the modem receives the ping and sends it to your computer, and your computer decided what to do. Now a days these smart broadband modems receive a ping and replies at the sometime it sends it to your computer! Example I got sprint DSL last December i went to shieldsup, and it said all my ports were closed, which is good but not the best. I went into my modem, same way you went into your router, by a web page, and set security. I reran the test and got Stealth on some of the common ports. I went to walmart and bought a four port router. I went into the router and set it up so it drops any pings from the wan (one click), reran the shields test and got the same readings, so I know it is the modem doing it. I can setup rules like you are trying to do, but I cant do it from a web page, I have to use telnet to do it.
About your rules I think if you swap the source and Destination it will work. Change, Deny,Source=LAN,Destination=WAN,IP start = *, IP end = *, protocol = All, Start port=* and end port=*, time = always.
To using Deny,Source=WAN,Destination=LAN,IP start = *, IP end = *, protocol = All, Start port=* and end port=*, time = always.
That should block anything coming in, and let you get out.
Come see me at Systematic Investing group #board-966 lets talk formula plans.