I'm lucky enough to have a router that can do custom firewall rules, so it's as simple as:
1) set up a static IP on the ps3 to be locked down
2) drop this line in the outbound firewall rules:
drop from addr 192.168.xxx.xxx >> done
Then nothing from that address gets out, period. FTP on the local side still works fine. With two ps3's there is no real need for the locked down system to connect to the net. If I need a game update or something I get the link using connection sharing, wireshark, and my updated ps3.