Many (mostly small) companies deploy the simple allow-everything-outbound
rule. AFAIK the pogoplug will initiate the "connection", and therefore
work happily with these setups.
Of course this is also true for most P2P and assorted malware, with the
difference that pogoplug is not using sneaky techniques (tunneling over
http, https, dns, whatever).