The issue was the same with HTTPS. HTTPS does not prevent the problem since the firewall was blocking all OPTIONS request.
I'm curious: with HTTPS, how does the firewall know that it's an OPTIONS request ?
By firewall, he would have to be talking about a client side firewall running on the machine making the request. Something that sees the request before it actually goes out on the wire.
You are right, I have tested it again and HTTPS is working since the firewall cannot decode headers.