is this reasonable?
iptables -A OUTPUT -o lo -j ACCEPT iptables -A OUTPUT -o eth0 -m conntrack --ctstate NEW -j DROP