Keep in mind though that crafty users will always find ways around these things. I work at a school, and no matter what we block, there's always some other service that takes its place. For instance AIM has a web based interface that runs over port 80. In a case like this, you will need to block packets from that one domain, which may cut out half, if not most of AOL, which makes for ugly, mad users.