Hi Tom, sorry if i re-open this, i have another issue now, i dunno if is something of shorewall or the tproxy support.
It's your configuration. You don't have an ACCEPT rule for port 80 from lan to fw.
And please let me know if that works so I can update the HOWTO. I didn't have the software to properly test TPROXY support when I developed it, so I could only verify that it was generating the same rules as were recommended in the HOWTO that I followed.

Well, i set the rule for allow lan to fw port 80, now there is nothing show on /var/log/firewall.

But navigation is not working, and when i check squid logs shows : http://pastebin.com/b0j3rjhH