K-8 school here trying to block students using VPNs: could be apps or websites, on either Chromebooks or phones. Our content filter, iBoss, is not good in this area, only offering to block five ports. I want to block lots more, hoping to catch not all but the majority of ports commonly used by VPNs. I think ZD can do this in configure>access control. But which section? L2? L3/4? "Application Denial Policy"? See two attached screenshots.
![Image_ images_messages_5f91c3f4135b77e2478f8b15_c5287280e4596ec52c58071c37e5eaaa_RackMultipart20181113122823vmz-495ab65f-5bde-4adf-817d-d9599282cbaf-20146621.jpeg1542140629 Image_ images_messages_5f91c3f4135b77e2478f8b15_c5287280e4596ec52c58071c37e5eaaa_RackMultipart20181113122823vmz-495ab65f-5bde-4adf-817d-d9599282cbaf-20146621.jpeg1542140629](/t5/image/serverpage/image-id/1378iCAF3B4BBB5759CCA/image-size/large?v=v2&px=999)