--I know next to nothing about iptables, even went thru some HOWTO's and got nothing but mind-boggled. So I googled for "iptables basic protection" and a few other things, and hacked together a basic-protection script with the help of various sources.

--Anyone who knows ins/outs of iptables security, please examine and see if there's anything redundant or useful that can be added.

--Script as supplied is pppoe-centric (ppp0):
o Allows loopback 127.0.0.1
o Allows ping from inside and outside boxes
o Allows bittorrent
o Allows ssh
o Allows squid (port 3128)

o Disallows nmap except from localhost
o Blocks certain known-bad Windows ports.

--So far I haven't tested it yet for VNC or ssh port-forwarding. Bittorrent definitely works tho.

--Note: I had to re-edit and jump thru some hoops for ssh to work properly. First crack at this, my existing ssh session died. Then the existing session stayed, but I couldn't reconnect with a new session. The existing rules are a lot now, but allows ssh to work as you would expect. I'm wondering if I can cut this down a bit tho, and optimize it.

--In this post, I'll put the basic code; the full source with references and comments will go into a reply-topic. TIA.

Code:
#BEGIN basic-prot
#!/bin/sh
iptables -F
 iptables -X
 iptables -A INPUT -i lo -p all -j ACCEPT
 iptables -A OUTPUT -o lo -p all -j ACCEPT
 iptables -A INPUT -j ACCEPT -m state --state ESTABLISHED -i eth0 -p icmp
 iptables -A INPUT -j ACCEPT -m state --state ESTABLISHED -i eth0 -p tcp
 iptables -A INPUT -j ACCEPT -m state --state ESTABLISHED -i eth0 -p udp
 iptables -A INPUT -p icmp -j ACCEPT
 iptables -A INPUT -i ppp0 -m state --state ESTABLISHED,RELATED -j ACCEPT
 iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
 iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
 iptables -A INPUT -p tcp --sport 22 -j ACCEPT
 iptables -A INPUT -p udp --sport 22 -j ACCEPT
 iptables -A OUTPUT -p tcp --sport 22 -j ACCEPT
 iptables -A OUTPUT -p udp --sport 22 -j ACCEPT
 iptables -A INPUT -i eth0 -p udp --dport 22 -j ACCEPT
 iptables -A INPUT -i eth0 -p tcp --dport 22 -j ACCEPT
 iptables -A OUTPUT -o eth0 -p udp --dport 22 -j ACCEPT
 iptables -A OUTPUT -o eth0 -p tcp --dport 22 -j ACCEPT
 iptables -A INPUT -s 0/0 -p tcp --dport 8080 -j REJECT
 iptables -A INPUT -s 127.0.0.1 -p tcp --dport 3128 -j ACCEPT
 iptables -A INPUT -s 10.0.0.0/8 -p tcp --dport 3128 -j ACCEPT
 iptables -A INPUT -s 0/0 -p tcp --dport 3128 -j REJECT
 iptables -A INPUT -p tcp -s 0/0 -i ppp0 --dport 6881:6889 -j ACCEPT
 iptables -A INPUT -p tcp -s 0/0 -i ppp0 --dport 6969 -j ACCEPT
 iptables -A OUTPUT -o eth0 -p tcp --dport 31337 --sport 31337 -j DROP
 iptables -A FORWARD -p tcp --sport 137:139 -j DROP
 iptables -A FORWARD -p udp --sport 137:139 -j DROP
 iptables -A INPUT -s 10.0.0.0/8 -i ppp0 -j DROP
 iptables -A INPUT -s 127.0.0.0/8 -i ppp0 -j DROP
 iptables -A INPUT -s 172.16.0.0/12 -i ppp0 -j DROP
 iptables -A INPUT -s 192.168.0.0/16 -i ppp0 -j DROP
 iptables -A INPUT -i ppp0 -s 10.0.0.0/8 -d 0.0.0.0/0 -j DROP
 iptables -A INPUT -p tcp -s 0/0 -d 0/0 --dport 1214 -j REJECT
 iptables -A INPUT -p tcp -s 0/0 -d 0/0 --dport 139 -j REJECT
 iptables -A INPUT -p tcp -s 0/0 -d 0/0 --dport 445 -j REJECT
 iptables -P INPUT DROP
 iptables -P FORWARD DROP
 iptables -A INPUT -p tcp --tcp-flags ALL SYN -j DROP