I have a small network and i would like to ask if my firewall is OK. My setup has a pppoe connection through eth1 and it is named pppoe-out1. Then i have bridge that has ports eth2-5 and it is named bridge1.
here are my firewall rules
/ip firewall filter
add action=drop chain=input comment="Drop connections from 117.202.127.0/24" \
src-address=117.202.0.0/16
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=input protocol=icmp
add action=drop chain=input in-interface=!bridge1
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=input protocol=icmp
add action=drop chain=input in-interface=!bridge1
add action=accept chain=forward connection-state=established
add action=accept chain=forward connection-state=related
add action=reject chain=forward icmp-options=8:0-255 in-interface=!bridge1 \
out-interface=pppoe-out1 protocol=icmp reject-with=icmp-host-unreachable
add action=reject chain=forward icmp-options=17:0-255 in-interface=!bridge1 \
out-interface=pppoe-out1 protocol=icmp reject-with=icmp-host-unreachable
add action=reject chain=forward icmp-options=15:0-255 in-interface=!bridge1 \
out-interface=pppoe-out1 protocol=icmp reject-with=icmp-host-unreachable
add action=reject chain=forward icmp-options=30:0-255 in-interface=!bridge1 \
out-interface=pppoe-out1 protocol=icmp reject-with=icmp-host-unreachable
add action=drop chain=forward port=0 protocol=tcp
add action=drop chain=forward port=0 protocol=udp
[admin@MikroTik] /ip firewall filter>
Is it OK, or am i missing something?