Think about your threat model and what you need to protect against. A firewall per se adds nothing. A proper configuration is required that might not be easy for a „noop“.
Do you need Internet when processing the „classified“ information? If not, easiest solution would be to do it offline from a live cd or hardened system.