Thank you for the answers,
About the firewall, I may have expressed myself poorly. I meant that I'm to clear the rules that prevent access to certain websites which isn't being properly blocked by squid (like facebook).
I'm probably going to try the WAPD package (in 2 weeks, when the proxy tests are scheduled). Since, as KOM said, Outbound NAT rule may give me some false-positives of MitM attacks.
The company specified that no branch office is supposed to have a proxy anymore. According to them it may interfere with the Net balancing, since we have two links, from the same provider, one for the internet and the other for the corporate net).
And I'm definitely not going to manually configure the browser of 300 hosts. ;D
Once again, thank you all.
I would appreciate if this topic could remain open for 2 weeks, I may get in some trouble with WAPD.