Dwall is an all-purpose firewall tool to generate an iptables firewall out of a simple configuration. It contains about 80 predefined services and comes with a simple 3 zone firewall example.
In essence the sysadmin only needs to define the different zones and define what traffic is allowed from one zone to another (if any).