By the way ..
According to my own arguments above a more sofiticated firewall controll should require som much more configuration tools so it should not be practical to implement to the server-manager panel.
But one thing that actually cold be implemented rather easy is lets say a 2 alternative choice:
A. Lan open mode, like today, with free access out.
B. Lan secure mode. Outgoing trafic restricted to web proxy and mail only (or possible some other basic functions.)
Personally I would never like to use such a "secure mode", at all, but there might be other users and other needs like for children and business environment with higher secuity requirements etc.
The firewalling part of such a mod should be rather easy. Dont know about the config-panel part of it.
I have used a modifyed sme gateway (5.6) with such a resticted "communication profile" it worked ok technically but the users (students) were not very happy about having just a few internt services available. (So it ended with "please open it again" and so we did.)