So, this is my second CHR firewall firewall config (allow only icmp from remote network): [admin@MikroTik] > ip firewall filter print Flags: X - disabled, I - invalid, D - dynamic 0 ;;; Accept - established, related chain=input action=accept connection-state=established,related log=no log-prefix=&qu...