Arp Spoof the entire network (with permission) so all the clients are going through your machine. (MAKE SURE it is capable of handling the amount of connections and that you're forwarding the traffic to the gateway so you won't experience a network wide DoS.)
You can also set up a new server as a router which uses perhaps an IDS to monitor the connections made and instead of possible intrusions it is configured to detect sites such as facebook.com etc.
There is a third alternative and that is to use an enforced web proxy such as Squid.
Well, I hope it helped just a little bit
