what should be proper order of these rules and why ?
Code: Select all
add chain=forward comment="Accept established and related packets" connection-state=established,related
add action=drop chain=forward comment="Drop new connections from internet which are not dst-natted" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
add action=drop chain=forward comment="Drop invalid packets" connection-state=invalid
If i do not choose any interface will following rule apply to every source interface?
Code: Select all
add action=drop chain=input comment="DROP ALL IN INPUT CHAIN"