During the Sophons setup I could see that all my clients were connecting to 176.34.185.65 ( mcs1-bc47.broker.sophos.com) via port 443 and not using the proxy . This should be using the existing proxy configuration in place
My bad as I totally forgot to enable this. However it seems that during the update process the are still connections that go to port 80 and are via the pf instead of the proxy
For example after the initial connection to the broker.sophos.com (during the download) it gets the files from (in my case ) using port 80