You could specify a specific DENY rule in the firewall disallowing any connection to those IP addresses, is a bit of a pain though.
Purchase a web filtering appliance or Websense/WebMarshall to filter things properly for you...
Michael Firth
Network Infrastructure Officer
~If it's not broke, break it and LEARN~