At present its a workgroup network and have installed Linux with Iptables as the Firewall.

In the rules as u mentioned ,generally everthing is flushed and denied and then only the respective ports are given access.

So theres no proxy server present.Actually my company has told me do design a network ,w.r.t

denying intrernet access to certain groups and only mail access
in local lan groups to be made ,so that they dont access each other.
disaster recovery and backup strategies
vpn

I cant post the network diagram which i have percieved as theres no option.If u have any mail id ,i will attach the same and u can correct me .