That's pretty much what the idea is, AFAIK.
Shut off every service except for VPN/SSH, use pregenerated key pairs for authentication (4096 bit keys? Longer?) and anybody who jumps on the network gets a connection that goes nowhere. If you have a key, you VPN to 192.168.0.1, and voila! you're internal again.
Gimli's Rules for Surviving in Middle Earth #43: When attempting to destroy an artifact, remember to use somebody else's axe.