Hi, My bad. My objectives behind the rules are as follows. 1. I need to prevent someone from the internet accessing the router. This could via telnet, ssh, ftp, winbox etc. 2. I want to block or at least slow down port scans. 3. if I have malware on my internal network, then that malware should not ...