I do not see that behaviour on my 184.108.40.206.
I have a rule that blocks on this criteria:
Header.Request.Get ("Via") matches *192.168.2.232*
And when i forward from another proxy with that IP address, it blocks as it should.
This rule is at the top in only the request cycle, then i have another rule below that in the request/response cycle that removes the Via header as it goes out to the internet.
i don't know why it wouldn't work for you.