That could be the case. This firewall has been upgraded 2-3x since R77(?).
The rule that accept this traffic is the General Web rule we have that allows outbound HTTPS
Source: Internal Network Range
Destination: Negated (cluster)
Service/App: http/https
There is also another rule that allows admins access to any service/apps.
With this rule I reach the generic web error. With the rule above, the end user reaches the "ERROR...failed to connect to the WWW server".
Source: Admin Account
Destination: Any
Service/App: Any
Hope that helps.