Kelli-
there are many different types of firewalls, some good and some not so good. Alot depends on what your budget if any is for something like this. But, with that said, you can do something like buy (or borrow) an older PII 300-400 and throw BSD or Redhat on it for the OS and then use one of several firewall packages or the cheap way which is IP Chains.
Another option is to get a PIX 501 or 506 depending on user count need and traffic. Get them used off ebay and save a few bucks. An old webramp firewall which is really a Sonicwall with a 25 user license can be had for under 60 bucks.
internet---firewall--------router-----LAN
|---------DMZ where the DNS and webservers live
Forgive the ASCII art.. it's tough to draw here
So you can see there alots of options for a firewall of some type. ranging from almost free to several hundred dollars.
You want to set up an extended access list which will let you specify which ports to block on a IP or range of IP address.
I'm sure there are more then a few threads of how to set it up, I just posted something a few weeks ago that went into quite a bit of detail.. darned if I can find it now.
I can suggest a decent book on access lists called Cisco Access Lists by O'Rilley
A second choice (I have both) is a field guide to access lists
You could not really go wrong with either one.
MikeS
Find me at
"Take advantage of the enemy's unreadiness, make your way by unexpected routes, and attack unguarded spots."
Sun Tzu