The default block all incoming and allow all outgoing works fine for me. ARP and such won't traverse the router and the VPN should be a full tunnel, so no device info except the travel router itself should leak.
OpenWrt Travelmate is great for this purpose.