$IPT -F
$IPT -P INPUT DROP
$IPT -P FORWARD DROP
$IPT -P OUTPUT DROP
#LAN to WAN
$IPT -A FORWARD -i $LAN_IF -s $LAN -m state --state NEW,ESTABLISHED -j ACCEPT
$IPT -A FORWARD -i $WAN_IF -m state --state ESTABLISHED -j ACCEPT
#LAN to localhost (SSH)
$IPT -A INPUT -i $LAN_IF -p tcp --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
$IPT -A OUTPUT -o $LAN_IF -p tcp --sport 22 -m state --state ESTABLISHED -j ACCEPT