Even though the firewall shields the router from the general public interface, you should still want to disable RouterOS expert services.The main rule accepts packets from currently proven connections, assuming they are Secure to not overload the CPU. The second rule drops any packet that connection tracking identifies as invalid. After that, we se