Unfortunately I overlooked the config. There's already an automatic rule that 
whitelists all VMs that are marked to 'Allow connections to Updates proxy' to 
connect to the proxy on port 8082, therefore my suggestion would not work 
(specially given the fact that the rule to block all traffic is added at very 
top of the FORWARD chain).
So is there any way to use the same mechanism to use the proxy on the sys-net 
while forwarding the traffic to the sys-firewall?

