You can manually configure netfilter interactively from shell, save its state with iptables-save, and restore it via init script with iptables-restore upon system reboot. The iptables of Debian provide packet filtering, network address translation (NAT) and other packet mangling. There are some helper applications which can assist you setting up iptables, all of them available in the repos:
If you are in doubt, and want a “quick & easy” solution, choose firestarter or gufw.