Without deep packet inspection hardware its a losing battle. SSL VPN runs over 443, and really, you can run any protocol over any port, so you can tunnel any of those other VPN type apps over 80.
Use tools like DPI to identify the source, and then TOS to eliminate or reign in the source. As others have noted, this is the only way.
__________________
-Scott
|