Here's what I ended up with. Is there anything I should change for security?
# Generated by iptables-save v1.3.0 on Tue Jan 10 20:06:56 2006
*filter
:FORWARD DROP [0:0]
:INPUT DROP [134:9682]
:OUTPUT ACCEPT [168:16511]
-A INPUT -s 127.0.0.1 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
COMMIT
# Completed on Tue Jan 10 20:06:56 2006
|