The only real way that i know of is not allow "direct" internet access and have everyone go through a proxy server (and have the proxy server block the aim traffic). In the aim client there is a way to have it detect an open port for it to use (could be anything from telnet, ftp, port 80, etc).
|