Block incoming traffic

Hello,

I have a CHR that I use in Bridge mode.

I want to block all external traffic from certain ip-addresses on my network (except the ip addresses and ports that I added to the whitelist)

But I want these IP addresses not to interrupt the exterior Internet exits.

How can I do this procedure in a simple way?

Can you help me?

thanks