PPPOE >> internet >> firewall rules must have?

Hello
I have mikrotik hex for main modem

pppoe conection to internet

what is must have rules for firewall filter rules?
So nobodoy can to my mikrotik via ftp,telnet,ssh etc ?

because, right now i have something, and i have problem with iptv channels
Iptv channels are working till 1.12.2018 cca
Config is old year+, and nothing changed, so i cant figure out what is wrong, so i need start again from clean start :frowning:
in attach i give what i have
first some rules are for local wifi network, so i delete here
problem gone if i disable rule no.11

11 X  ;;; NET firewall rule
      chain=forward action=jump jump-target=OUTPUT-Internet 
      out-interface=optika log=no log-prefix=""

firewall.rsc.txt (9.42 KB)

If you suspect any sort of compromise or hack into your firmware then you should upgrade to the latest firmware using netinstall.
That would be the best place to start. 6.43.8 is the latest firmware.

Then following this guidelines is a good idea…
https://wiki.mikrotik.com/wiki/Manual:Securing_Your_Router

rb hex is up to date, read my question
tnx

update

i downgrade 6.43.8 to 6.43.4
And my firewall rules working good, iptv is now normal

so, what is problem?? Some new fix broken rules or rules broken new sw 6.43.8 ??