Here's one bug found.
In the HTTP Proxy create a web filter (I made one to restrict everything but web mail). Then in Access policy create the rule for some IP using that web filter and make it active.
It blocks everything, but mail - ok.
But when I turn off the access policy rule, it continues using the web filter. Even deleting the access policy rule doesnt change the behaviour.
I've just deleted the web filter profile and it still says: "Access control configuration prevents your request from being allowed at this time."