ros code
/ip firewall filter
add chain=input comment="default configuration" protocol=icmp
add chain=input comment="default configuration" connection-state=established
add chain=input comment="default configuration" connection-state=related
add chain=input dst-port=67,68 in-interface=ether1-gateway protocol=udp src-port=67,68
add action=jump chain=input comment="default configuration" in-interface=ether1-gateway \
jump-target="log and drop"
add chain=forward comment="default configuration" connection-state=established
add chain=forward comment="default configuration" connection-state=related
add action=drop chain=forward comment="default configuration" connection-state=
add action=jump chain=input dst-port=22 in-interface=pppoe-out1 jump-target="lo
protocol=tcp
add action=jump chain=input dst-port=23 in-interface=pppoe-out1 jump-target="lo
protocol=tcp
add action=jump chain=input dst-port=21 in-interface=pppoe-out1 jump-target="lo
protocol=tcp
add action=jump chain=input disabled=yes dst-port=80 in-interface=pppoe-out1 ju
"log and drop" protocol=tcp
add action=drop chain=input dst-port=53 in-interface=pppoe-out1 protocol=udp
add action=jump chain=input dst-port=53 in-interface=pppoe-out1 jump-target="lo
protocol=tcp
# ppp-out1 not ready
add action=jump chain=input dst-port=22 in-interface=ppp-out1 jump-target="log
protocol=tcp
# ppp-out1 not ready
add action=jump chain=input dst-port=23 in-interface=ppp-out1 jump-target="log
protocol=tcp
# ppp-out1 not ready
add action=jump chain=input dst-port=21 in-interface=ppp-out1 jump-target="log
protocol=tcp
# ppp-out1 not ready
add action=jump chain=input dst-port=80 in-interface=ppp-out1 jump-target="log
protocol=tcp
add action=log chain="log and drop"
add action=drop chain="log and drop"
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" disabled=yes out-interface=ether1-gateway
add action=masquerade chain=srcnat out-interface=pppoe-out1
# ppp-out1 not ready
add action=masquerade chain=srcnat out-interface=ppp-out1
add action=dst-nat chain=dstnat disabled=yes dst-port=53 protocol=tcp to-addresses=192.168.10.1 to-ports=53
add action=dst-nat chain=dstnat disabled=yes dst-port=53 protocol=udp to-addresses=192.168.10.1 to-ports=53