Packet filtering alongwith other measures should work. IPchains is good try it out. Also use tools like dsniff and nmap to check the security of the network.Shutdown services which are not needed. And block all ports which are not in use.
...and follow the paranoid approach to security. ``Deny all, allow selectively.'' You should be enough secure that way... :)
--amar
-- Amarendra A. Godbole / Microsoft ``Services For UNIX'' / These opinions are _MINE_. If anything can go wrong, _FIX_ it. (To hell with MURPHY)