mark1171 wrote:MattP;
I a Professional version, so cannot block apps.
Oh you can still block apps - you just don't have the central administration feature of the Enterprise version.
How many end users/machines are we talking about? How computer savvy are they? What OS is on the client machines? In my experience the WGIC does a good job of letting WG know about the machine, user and app trying to connect. However, I have seen smart users change the name of the app to sometthing else and circumvent some of the policies.
MEssenger can also be set up to use a proxy - In Messenger, Tools-> Options-> Connection select proxy server and choose socks 4 or 5 then Insert name of WG machine. Then set up SOCKS proxy server in WG with approprate policies. Client will receive message box frrom messenger saying something is wrong with connection etc if you restrict this proxy. This might be an alternative for you. However it is relatively easy for end user to change back to NAT setting -so that's why I ask question about how smart your end users are.
Also depending on your client machines OS you can develop a local security policy not to allow software to run.