It is more of a GUI limitation at the moment. Technically the new firewall core can handle IGMP (and a lot more protocols for that matter) just fine, but the GUI doesn't offer any control for it and currently does fall back to allow it in case of IGMP to not break some streaming setups. There are a ton of protocols out there. Some are less obscure than others. So adding everything to the GUI will result in excessive complexity. We are currently debating about adding a single option to drop all packets that aren't supported by the GUI, but haven't made a decision yet.