http://nguipxnkrp3qrzrlduhsatpcpwehnblzmlkc5ifiumxq4z5jlh4lwvid.onion/os_archive/os_Internet_Security.html
The first line in your firewall chain on you router should be: BLOCK ALL INCOMING BLOCK ALL OUTGOING. What ever way that is set up according to your router. Then slowly open things up, starting with DNS, then HTTP, HTTPS, then whatever other ports and protocols you need.