I prefer IDS/IPS + custom DNS services like OpenDNS or AdGuard as a protection layer (with enforced rules for DNS queries), instead of proxy, in "office" environments.
But this is just me.
I know the headaches a proxy server can give to you in such environments if it's not properly maintained. IDS/IPS needs some attention as well in the beginning, a few days to see what's being blocked (and to allow stuff if necessary). General performance is just poor and waste of resources with proxy, this is how it works. "Unrestricting" ips sounds like making the proxy server almost useless...
It has its own applications, no doubt about it, maybe you really need it, but also maybe you can try protecting your network is some other ways and would be good enough. I'm not trying to make you change your mind here, just consider other stuff as well.
This is a good article describing various protection techniques, many of them available in OPNsense as well:
http://resources.infosecinstitute.com/network-design-firewall-idsips/
Otherwise, you need to debug your proxy setup. Since it has been a long time since i didn't use proxy, i forgot many details about it. What i do remember, is that you need proper security certificates to make it work in https as well, not just http (without the need to trust CAs and other stuff with every client), a powerful box if you have many proxy clients, caching properly configured, and many other aspects...
But this is just me.
I know the headaches a proxy server can give to you in such environments if it's not properly maintained. IDS/IPS needs some attention as well in the beginning, a few days to see what's being blocked (and to allow stuff if necessary). General performance is just poor and waste of resources with proxy, this is how it works. "Unrestricting" ips sounds like making the proxy server almost useless...
It has its own applications, no doubt about it, maybe you really need it, but also maybe you can try protecting your network is some other ways and would be good enough. I'm not trying to make you change your mind here, just consider other stuff as well.
This is a good article describing various protection techniques, many of them available in OPNsense as well:
http://resources.infosecinstitute.com/network-design-firewall-idsips/
Otherwise, you need to debug your proxy setup. Since it has been a long time since i didn't use proxy, i forgot many details about it. What i do remember, is that you need proper security certificates to make it work in https as well, not just http (without the need to trust CAs and other stuff with every client), a powerful box if you have many proxy clients, caching properly configured, and many other aspects...
"