There were no relevant WFC events in the two event viewer locations given in the FAQ. Uninstalling and reinstalling did fix the problem, and it was not immediately repeatable. But it did break notifications as well. I am currently developing my base rules, just using DNS has appeal, but I prefer to have notification High and use blocking rules for the behaviors I don't like. This would be made easier by the following Enhancement request: On the connections page, mark the blocked packets not associated with a rule in a different color or some other way. Then you can connect and just hit block for now on all the notifications and then peruse the log later and see what they were.