Apparently, I don't know what I'm doing...

If I turn off Transparent HTTP Proxy my users are able to browse directly
to the Internet. So my thinking is why would I need to have Transparent
Proxy enabled. Except with it disabled, no Access Rules are enforced,
namely my SurfControl filter. What am I doing wrong? Does Bordermanager
not enforce access rules unless you use Transparent Proxy? My workstations
have nothing configured on them in regards to a proxy. They find their way
out through routing.