I would like to block certain types of inbound traffic on my hotspot interface, as soon as it enters the router before any hotspot processing etc takes place.
What chain would I use for these rules? Any other catches? I have tried a few ideas with no luck.
The correct chain will most likely be forward. This is true if you are blocking traffic that is between your LAN clients and any other location which is not the router. If you are blocking traffic that is directed to the router, the chain will be input. With the hotspot in place, its sometimes easier to disable the dynamic hotspot rules for troubleshooting purposes.