Block all traffic, then allow specific ports & addresses

Hi all, I have my MikroTik hAP router set up with 2 subnets (on ports 3 & 4) which seems to be working.

I now want to create a completely locked down system that no traffic can flow, in either direction, between my internal network (ports 3 & 4) and the internet (on the internet port). I will then start, one at a time, to add specific rules (ports and addresses) to allow certain traffic through.

Is anyone able to offer some advice on how to achieve this? My assumption is that maybe there is a single rule I can add to the firewall to block all traffic, then add additional rules which are the exceptions to the block all rule?

Thanks in advance

https://forum.mikrotik.com/viewtopic.php?t=180838