Instead of doing that, you could ensure that whatever device connects him to the internet (modem/network card) has only tcp/ip bound to it - nothing else - and if he's running an NT server he should have /some/ sort of firewall anyway, its common sense.




