I though I was having this same issue. I found that putting the ID in the Security rule IDs box and clicking Apply did not cause the rule to be instantly disabled. Something needed restarting (not sure if it was apache, or nginx, or something else). By switching that domain to Detection Only and...