The main thing I was going for is that nothing should be incoming other than ftp,http and https to 10.0.0.24, and that the box should provide normal internet access for all the computers on my LAN. eth0 is my connection to the internet and eth1 is my LAN.