There are "Filter local ..." flags in the Options: IP Addresses: LAN, which are ticked off by default.
So the LAN addresses are always auto-allowed by default.
Also this rule will block all incoming ICMP requests too, so you can't ping your machine from Internet (if you are not behind router).
Should I replace "local_port" with "port" to work?
I want when allowing program to connect, to have only outbound traffic, while blocking all inbound one.