The Z1 appliances only run the Enterprise license, they cannot run the Advanced Security license that has the full web content filtering you might be asking about, on the Z1 you basically just have the firewall page for L3-L7 rules.
I would double check the firewall rule configuration and make sure you have the appropriate permit rules in place, for example if you have multiple VLANs and the MX will be providing the interVLAN routing and you want to allow such LAN-to-LAN traffic. Let me know if I misunderstood.