Webmail vs. plain mail client doesn't impact your target design, at least here. so, yes, you can go with webmail.
If I understand your point, I would propose this:
- as external PO3 mailboxes exist and you want to keep it, enable transparent POP3 proxy and active "filter spam" and "filter proxy"
- for outgoing mail, be sure to have enabled SMTP filtering options. It may make sense to prevent users to directly access their current "external" SMTP server so that they have to use Zentyal et benefit from such service.