I had a problem with an employee hogging all the bandwidth by using bit torrent etc, he is a good worker though so I didn't want to get rid of him, anyway my solution was.
BLOCK all ports and just leave open the ones for http and emails etc...works perfectly, and then I have a timer built into the router that allows them to become open again for him, outside of office hours...
|