Some thing have learned:
At the DC level, and options, make sure Input and Output policies are both set to ACCEPT. Otherwise when you enable the firewall at the DC level, you will get locked out of the GUI. (I think)
At the DC level enable the firewall, otherwise none of the firewall rules...