Wich mode do you use in http proxy? Depending on that there are different possibilities to block a user or a source ip. You could for example create networkdefinitions that exclude the one ip.
That was my thought - create networkdefinitions (or hostdefinitions) for the allowed hosts (in what way ever) and put that definitions(s) in the allowed networks of http proxy. Remember to check if there are packetfilterrules that will allow http traffic without the http proxy.