What does the rule trace tell you about your access? It could give you the answers.
I bumped into a similar scenario as this, a user's still being blocked even with a stop cycle action.
I've checked the trace, and found that my rule's only hitting request traffic. I applied the rule to response traffic as well and all has worked fine since.
You might want to check this. If you still have problems, you could share your trace here.
Yes .Thats how it works
It worked for me when I checked responses