Even though the firewall protects the router from the general public interface, you should still desire to disable RouterOS services.The main rule accepts packets from previously proven connections, assuming they are Safe and sound not to overload the CPU. The second rule drops any packet that relationship tracking identifies as invalid. Following