We have a company network spanning just over 40 sites and 5 countries.We have two web gateways and perimeter firewalls (with two content filters) for the whole IT estate. We generally lock down all inbound and outbound ports unless there is a business need for their use.Similarly, with web sites, we block access to any web categories which might present a threat to the company network.I would class 95% of our user base as non-IT orientated - they wouldn't know what "Operating System" they we were running, if asked (or indeed how to find out).Quite frequently, we get asked to allow access to Team Viewer and the many other similar services. The reason is usually to allow a third-party to assist one of our users with third-party software.This is something which we (as technical personnel) hate doing, due to the security implications.

