Review of PPPoE and Firewall rules for improvements

There are basically three “groups” of people on Mikotik forum with diverging opinions regarding firewall rules, let’s see if I can explain how I see the situation.

The first one, that we will call for simplicity “the rextenders” :wink: believe that the default firewall rules that Mikrotik provides for SoHo devices are good in 99.99% of normal user cases and can (at the most and only in particular cases) be integrated by a handful of specific targeted rules..

The second, that we will call for simplicity “the anavites” :open_mouth: believe that the default firewall rule that Mikrotik provides for SoHo devices are good for the most part, but the last rule in forward chain MUST be a “drop all else” one (which implies that just before it a number of explicit, narrowly targeted rules need to be inserted to explicitly allow whatever is desired to pass).

The third, that we will call for simplicity “the others” believe that they can put together a better firewall on the base of their own ignorance :laughing: ( built up on viewing youtube videos or reading the - seriously lacking - Mikrotik documentation or by asking for advice on ChatGPT and similia).

While there can be debate on whether the first or second group is “more right” than the other, the third group appears to invariably produce something that is almost, but not quite, completely unlike a valid set of firewall rules.

Which brings us back to the Rules of Mikrotik Club, specifically #8:
http://forum.mikrotik.com/t/the-twelve-rules-of-mikrotik-club/182164/1