Note that the rule associated with the PUBLIC_LAN interface group is disabled.
Clients using the PUBLIC_LAN interface are able to obtain IP addresses via DHCP. I find this surprising, as I thought the input chain rules would prevent this.
Is someone able to clarify the situation? Thanks in advance
Instead of trying to block with the firewall, just don't put the IPv4 DHCP Client or Server instances on the interfaces of the PUBLIC_LAN list. Who forced you to enable the instances on those interfaces?