This is done via the ' protection profile' feature, under the Firewall Menu.
Change your outbound rule to use a protection profile (create one first if required).
Create/Modify protection profile to enable the " URL block" under the " web filtering" sub option.
Add the domains which you want to block in the WEB FILTER -> URL BLOCK menu.
If you add " doubleclick.net" in there it will block the entire doubleclick domain.
If you want to allow access to other parts, then add four entries for the ones you mentioned (ie ns1.doubleclick.net ..... etc)
They will then be blocked for http.
HOWEVER, to block all traffic, you would have to work out all the IP addresses for each of those and add a deny rule to specifically block them.
If you do this, make sure the rule is at the top of RULEBASE POLICY.
UK Based Technical Consultant
FCSE v2.5
FCSE v2.8
FCNSP v3
Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.