Firewall Rule

Hi Everyone, I’m a new mikrotik user. I’m still a little confused with regards to firewall filter rules.

I need to do this rule on our network:

  1. Block SSH/Port 22 from outside but allow local access including VPN
  2. Block Winbox/Port 8291 from outside but allow local access including VPN

Is it possible to get help here how I would be able to do it?

Thank you very much