make network secure -- how?

hi,
I am new to routerOS. I have setup pppoe with Radius(freeradius+dialupadmin) successfully n things are working fine. Now i want to secure my router in all ways.

plz tell me which rule to use to block access to my router other than my pppoe users class(10.10.2.0/24) and a public ips subnet.

secondly i want to make sure that NAT should work only if 10.10.2.0/24 is a pppoe client/user.

anyother security precautions will be welcome too.

thanks in advance.

regds