I am continually playing with combinations. From Firewall Options Forward/Outgoing are Blocked. And Firewall Rules Incoming only allows TCP any/any HTTPS. Is that too liberal an Incoming Firewall Rule?
Following that reasoning, the Firewall InComing and OutGoing are Blocked and Blank/Empty. The Firewall functions. The Firewall Rules direct TCP to the Proxy Ports 800 and 3128. And DHCP UDP Source 68 and Destinatikon 67. But what is the DHCP Server under Network reporting:
Your Proxy Report shows all your requests ( from 192.168.5.3 ? ) are denied.
Have allowed internet ( web ) access for this device?
BTW: As mentioned many times in community threads ( and in the wiki also ) you should separate your subnets in green.