I saw this page but examples are poorly explained there. If I need to block any initiated from outside connection to router and LAN how should I change config? And why say nothing about NAT?Look at the information on filters here:
How can it be if any inbound is set to drop on WAN port?Example - If somebody on your ISP upstream network points traffic at your router for an RFC1918 address on your LAN then your router will pass that traffic.
As I wrote earlier "Main purpose just to have internet and iptv on LAN computer."Safe enough for what? That's hard to answer without knowing what your doing with it.
Indeed it works but is it safe enough? Also with this config router localhost can't go to the WAN/LAN ping etc don't work.Your original config is minimal, but should work.