Gentlemen,
Unless your VU+ box is directly connected to Internet or to a LAN network you don't trust, you shouldn't be implementing a firewall on your VU+ box but at the edge of your network (i.e. your Internet router).
It's not easy to get familiar with iptables syntax and philosohpy. Also, I recommend to use Firewall Builder (Google for it) as a visual policy editor for your FW rules.
A very good solution is to use an alternative firmware for your router such as openwrt or dd-wrt.
For the AV software it does make any sense: there are no known virus (should I say "yet"...) developed for the VU+. I doubt an AntiVirus sofware would be developed as Virii developers are targeting MS windows. Anyway, you can try to search for clamav which is a linux AV aimed at blocking virus for other systems such as MS Windows but I repeat myself: I doesn't make sense to install it on a VU+ box.
Always keep in mind that the security is must be seen as a whole. Like a chain it is as strong as its weakest link. So there is no sens to implementing firewall rules if you leave default password on.