Suppose in a company of N employees, you allocated an absolute cap of 1/N of the total upstream bandwidth to each Ethernet port. You wouldn't do that, because it would be slow. So you have to recognize that what you're doing is <i>over-committing</i> bandwidth. You are relying on less than N users sharing. But, bandwidth is a freebie to employees. They gain and don't lose if they maximize usage. That means that they can and will pour effort into subverting any and all firewall controls. That's a race you can't win.<p>Looking at it economically, what's the answer? Obviously, you have to start charging for bandwidth. Treat it as part of the department's budget.