Flags: X - disabled, I - invalid; D - dynamic
0 D ;;; special dummy rule to show fasttrack counters
chain=forward action=passthrough
1 ;;; to INET
chain=forward action=accept src-address=192.168.10.0/24
in-interface-list=LAN out-interface-list=WAN log=no log-prefix=“”
2 ;;; FOR Established connections
chain=input action=accept connection-state=established,related,untracked
log=no log-prefix=“”
3 ;;; FOR Established connections
chain=forward action=accept
connection-state=established,related,untracked log=no log-prefix=“”
4 ;;; defconf: accept ICMP
chain=input action=accept protocol=icmp
5 ;;; allow dst-nat from both WAN and LAN (including port forwarding)
chain=forward action=accept connection-nat-state=dstnat
6 ;;; for IP SEC
chain=input action=accept protocol=icmp src-address-list=AMX
in-interface-list=WAN log=no log-prefix=“”
7 ;;; IKE IPSec
chain=input action=accept protocol=ipsec-esp in-interface-list=WAN
8 ;;; L2TP
chain=input action=accept protocol=udp in-interface-list=WAN
dst-port=500,1701,4500
9 ;;; defconf: accept in ipsec policy
chain=forward action=accept ipsec-policy=in,ipsec
10 ;;; defconf: accept out ipsec policy
chain=forward action=accept ipsec-policy=out,ipsec
11 ;;; defconf: fasttrack
chain=forward action=fasttrack-connection hw-offload=yes
connection-state=established,related
12 ;;; Config Access
chain=input action=accept src-address=192.168.10.0/24 log=no
log-prefix=“”
13 ;;; for IP SEC UDP
chain=input action=accept protocol=udp src-address-list=AMX
in-interface-list=WAN dst-port=500 log=yes log-prefix=“”
14 ;;; for IP SEC TCP IKEV2
chain=input action=accept protocol=tcp src-address-list=AMX
in-interface-list=WAN dst-port=4500 log=no log-prefix=“”
15 chain=forward action=accept src-address=192.168.10.18
dst-address=10.245.0.11 in-interface-list=LAN log=no log-prefix=“”
16 chain=forward action=accept src-address=10.245.0.11
dst-address=192.168.10.18 log=no log-prefix=“”
17 ;;; INVALID
chain=forward action=drop connection-state=invalid
connection-nat-state=“” in-interface-list=WAN log=no log-prefix=“”
18 ;;; INVALID
chain=input action=drop connection-state=invalid connection-nat-state=“”
in-interface-list=WAN log=no log-prefix=“”
19 ;;; INVALID
chain=forward action=drop connection-state=new
connection-nat-state=!dstnat in-interface-list=WAN log=no log-prefix=“”
20 ;;; VPN
chain=forward action=accept src-address-list=VPN
dst-address-list=Local-LAN
21 ;;; drop all else
chain=forward action=drop