In that case you'll be wanting a transparent proxy for his IP address (set up something like nocatauth http://sourceforge.net/projects/nocatauth/ - and on his ips run all outbound to 80 or 443 thru a transparent proxy that denies everything and then you enter a whitelist of sites he is allowed to visit. You'll also want to restrict all other incoming /outgoing traffic to keep him from learning the ways around this stuff.
__________________
“IN MY EXPERIENCE, SUSAN, WITHIN THEIR HEADS TOO MANY HUMANS SPEND A LOT OF TIME IN THE MIDDLE OF WARS THAT HAPPENED CENTURIES AGO.”
|