sockd with ipchains

I want to setup a dante server running on my corporate proxy server. What are the most secure rules to add to ipchains to allow the use of sockd from my local network? Is it possible to disable the access to the sockd by any external user at the firewall level (i.e. without the need to further secure sockd.conf)?

