R0: deny fragmented packets, stopping reassembly attacks
R1: allow all local services on the loopback interface
R2: allow all DNS requests
R3: allow all DNS replies
edit:
allow tcp/udp in/out to ip 255.255.255.255 to port 67 (bootp access)
allow tcp/udp in/out to ip 0.0.0.0 to port 68 (dhcp access)
R4: allow LAN-2-LAN access {restricted to 192.168.0.1--0.10}
R5: allow LAN access to the broadcast address for sharing requests/ print monitoring
edit: add port 138 to access WORKGROUP names, eg
ports {137,138,161}
/edit
R6: allow all print sharing
R7: allow all access to ftp, http sites
R8: allow all access to smtp, pop3, nttp (ie email + news)
R9: allow IP Protocol GRE (for VPN access)
R10: deny rpc queries
R11: specific site
R12: windows service in hotspots
rules for hotspot protection to trojans known on specific ports:
R13: 1047,1234,1492,1812,1978,1999,2002,2082,2140,2745,2773,2967,3127,3410,4444,5554,
R14: 6129,6711,6712,6713,6771,7215,7300,7301,7302,7303,7304,7305,7306,7307,7308,8787,
R15: 4156,8594,9000,9872,9873,9874,9875,9876,9999,
R16: 17300,27347,31378,36794,
R17-19: allow ICMP (ie ping)
R20-22: deny non-routed private networks
R23: deny everything NOT http (port 80)