But I haven’t really given those rules a test in the past year.
The problem with the Identification in the outbound traffic is that tracking is probably based upon the TLS certificate presented in the stream. By the time that information is picked up you could terminate a connection but TCP is already negotiated, so you can’t then switch the outbound WAN etc. (or it would be very tough)