Thanks, The Smoothwall FW I referenced in my post is a Linux based firewall with
http proxy - my internal machines don't use the router as the default gateway, rather
the internal address of the firewall.

I don't think the problem is related to http traffic though, and I guess I could block
a bunch of outbound traffic but that would break my ability to do lots of other things.
I'm trying to pinpoint just the right traffic that is bringing up the connection.