Yeah, invoke your script from /etc/rc.d/rc.local (after disabling
rc.ip_forward) by doing "chmod ugo-x /etc/rc.d/rc.ip_forward".

Be sure that your script can be repeatedly invoked safely.  That means
first set the policy of all chains to DENY, then flush the rules.

