Re-tested this morning after rebooting, just to be sure it was a setting and not a glitch. Yes, you have to give separate authorizations for each component that needs network access.
The downside here is that the firewall doesn't TELL you it's blocking something and ask whether you would like to allow this.
|