Since nft is now installed, I added my nft script to it, and it works fine so far. Everything which is not expclitly allowed gets blocked, also to the routed networks.
Since the nft script are much more readable than the old iptables-save thingies, I think this addon could survive the daily...