Hello everybody.

I've set up a proxy at a customers' site and set up an ACL to block some
domains (first of all facebook.com).

Now some clever users have discovered that they can use foreing external
proxies to avoid filtering.

What I was thinking to do, is to enable on my firewall LAN-->WAN *only*
my proxy's IP address, but the question is: how would I have to proceed,
as the client PCs still could be set their proxy settings?!

