Students going to the internet

We are using the Web Proxy as our firewall controller, but students are still going to web sites of their choice using:

openssh
putty
sshwindows
tunnelclient

They may also be using other programs, but these are the ones we found this week.

Could we receive suggestions as to how we can keep our students from visiting 3 letter word web sites?

in firewall filter, block everything in the forward chain, then make transparent proxy, and redirect all port 80 requests to your proxy in the router.

this will allow access only to http traffic. then, make use of the webproxy access list, and make regex rules that block all the bad things