Although the firewall guards the router from the general public interface, you should still need to disable RouterOS services.The 1st rule accepts packets from currently recognized connections, assuming they are Protected not to overload the CPU. The 2nd rule drops any packet that connection tracking identifies as invalid. Following that, we arrang