Purevpn seems to be sneaking past the appfilter block at the moment.
Its connecting to *.ptoserver.com and *.pointtoserver.com
WatchGuard M4600 (x2 Cluster)
Firmware : 12.4.1
These types of services almost always masquerade as HTTPS/TLS traffic -- APP control will attempt to work without content inspection on, but it works best when content inspection is on.
Any/All of the tips here can come in handy with helping stop these types of apps.
(Block Evasive Applications)https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/configuration_examples/block_evasive_apps_example.html
WatchGuard Customer Support