Please provide a screenshot of what you're referring to. It's hard to determine from your post. The 'any' in Access Control Policy should be there by default. You can add or remove custom zones based on the Objects you have created.
The first thing you should do is grep the access logs. That will help you identify if the traffic is being proxied and whether or not the traffic is actually being blocked. This link will help if you are unsure: http://goo.gl/G89tIF Next, if your tra...
Create an access policy and under Policy Member Definition > Selected Groups & Users you can add users or groups you want to add to this policy. Next, under Advanced you can select what you want to block Make sure this policy is towards the top of th...