I did some searching before I posted the question. Nothing really addressed the question of blocking an internal device from the Internet, but there were warnings not to go fiddling with iptables outside the LMCE firewall config page.
Sounds like I'll need to do this on the desktop itself (caught my 10 year old son playing runescape after I told him not to, he alt-tabbed when I walked in proving he knew he was doing something on the Internet he knew he wasn't supposed to).