take a look at firehol as it makes creating rules a snap and handles all the iptables rule creation
I have a tut covering setting this up:
http://gregsidberry.com/2008/10/22/buil … -security/">http://gregsidberry.com/2008/10/22/building-something-scalable-security/
hope it helps