One of the developers, who was on my team at Nortel, did the following:
He used an old box (a P-233 I think) running Linux as a hub/switch for his family-home network. To "firewall" the system, he shut down every port on that box except the ones being used by his broadband internet connection and the LAN. He then wrote a short JAVA routine that only passed his LAN transmissions. It also created an IP masque so that the P-233 was invisible to pings.
If you do JAVA or know someone who does, maybe they could whip you up a similar routine that is custom tailored to your specific needs. He said that the whole thing that he did was fewer than 20 lines of code.
Hope this helps.
Sleeping Dog