Hi Andy, thank you for your reply.
So do you allow everything out effectively from the network layer (assuming for that vlan), but restrict at the application level? So blocking VPN applications, social networking apps etc, allowing you to allow the social networking apps on a time based schedule?
Thanks
Simon