It's just like the title says, when you access the server through the IP:PORT, say 111.111.111.111:9443, the rule trigger (in this case the deny rule) but when you access it through DOMAIN:PORT, say example.com:9443, access is allowed by the proxy, i.e, it defaults to the allow rule in the default block.
It's just like the title says, when you access the server through the IP:PORT, say 111.111.111.111:9443, the rule trigger (in this case the deny rule) but when you access it through DOMAIN:PORT, say example.com:9443, access is allowed by the proxy, i.e, it defaults to the allow rule in the default block.