I don’t think you can do it with the web-gui.
It would be better with the CLI and since you have experience with IOS it won’t be that difficult.
The full tutorial for iptables can be found here.
You must add a DNAT rule to match the dport 80 packets (and dport 443 if you want https) of the subnet or IP range that has the computers you want to intercept, that changes the destination IP to 10.150.1.3:8080. Normally if the proxy uses its source IP address on packets then you won’t need to do anything else. If it keeps the original IP address as source you also need to redirect the answers from the wan interface to the proxy server again.