works fine, no complain, none of the router's ports (ssh, etc.) are visible from the internet, it isn't ping-able, no issue using the internet etc./ip firewall filter add action=drop chain=input in-interface=ether1
but going through the mikrotik docs, I see that I should add:
Why? I have added it but didn't notice any change really./ip firewall filter add action=accept chain=input connection-mark="" connection-state=established,related