получилось такое# разрешаем нужное
${fwadd} allow tcp from ${lan_net} to any dst-port 22,25,80,110,137,138,139,443,445,995,3306,5190 in via ${lan_if}
${fwadd} allow udp from ${lan_net} to any dst-port 53,137,138,139,445 in via ${lan_if}
# заворачиваем http трафик на сквид
${fwadd} fwd 127.0.0.1,3128 tcp from ${lan_net} to any http out via ${inet_if}
${fwadd} deny all from ${lan_net} to any in via ${lan_if}
# включаем nat
${fwcmd} nat 1 config ip ${inet_ip} log
${fwadd} nat 1 all from any to ${inet_ip} in via ${inet_if}
${fwadd} nat 1 all from ${lan_net} 1024-65535 to any out via ${inet_if}
но при таком раскладе я закрываю внутрисетевые порты, а не внешние