Hello Bro I first time try to create firewall rules,would you mind told me, how to do much better
0 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough
1 ;;; Related connections
chain=input action=accept connection-state=related log=no log-prefix=“”
2 ;;; Established connections
chain=input action=accept connection-state=established log=no log-prefix=“”
3 ;;; Drop invalid connections
chain=input action=drop connection-state=invalid log=yes log-prefix=“INVALID”
4 ;;; Drop telnet
chain=input action=drop protocol=tcp src-address-list=telnet_blacklist dst-port=23 log=no log-prefix=“”
5 chain=input action=add-src-to-address-list connection-state=new protocol=tcp src-address-list=telnet_blacklist
address-list=telnet_blacklist address-list-timeout=none-dynamic dst-port=23 log=no log-prefix=“”
6 ;;; UDP
chain=input action=accept protocol=udp dst-port=“” log=no log-prefix=“”
7 ;;; ICMP
chain=input action=accept protocol=icmp log=no log-prefix=“”
8 ;;; Allow PPTP
chain=input action=accept protocol=tcp dst-port=1723 log=no log-prefix=“”
9 ;;; Allow PPTP
chain=input action=accept protocol=gre log=no log-prefix=“”
10 ;;; From local net
chain=input action=accept src-address=192.168.1.0/24 log=no log-prefix=“”
11 ;;; UDP
chain=forward action=accept protocol=udp log=no log-prefix=“”
12 ;;; ICMP
chain=forward action=accept protocol=icmp log=no log-prefix=“”
13 ;;; Allow Winbox
chain=input action=accept protocol=tcp dst-port=8291 log=no log-prefix=“”
14 ;;; Allow Webfig
chain=input action=accept protocol=tcp dst-port=80 log=no log-prefix=“”
15 ;;; Allow NAS
chain=forward action=accept protocol=tcp dst-port=21,8080 log=no log-prefix=“”
16 ;;; Allow iWinbox
chain=input action=accept protocol=tcp dst-port=8728 log=no log-prefix=“”
17 chain=forward action=fasttrack-connection connection-state=established,related
18 chain=forward action=accept connection-state=established,related
19 ;;; Drop everything else
chain=input action=drop log=no log-prefix=“DROP”
20 ;;; Drop invalid connections
chain=forward action=drop connection-state=invalid log=no log-prefix=“INVALID”