I realize how simple it is to do with iptables and
ipchains. I've used them both. You're right, the
limitation is the firewall (that is able to do very
complicated tasks, just not block on domain names).
If it were up to me, the bosses would create a firm
policy with drastic consequences. I'm using what I
have to work with. (It's a typical topdog/businessman
type of request...do it fast without costing money)