Reverse firewall
Something like this maybe?
# Assuming no pre-existing rules - don't just run this!
for PUBLIC in 22 80 443 # Your public ports
do
iptables -A INPUT -p tcp --dport ${PUBLIC} -m conntrack --ctstate NEW -j ACCEPT
done
iptables -A INPUT -j REJECT
iptables -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -P OUTPUT -j DROP