Even though the firewall guards the router from the public interface, you should still wish to disable RouterOS expert services.The very first rule accepts packets from previously proven connections, assuming they are Harmless to not overload the CPU. The 2nd rule drops any packet that connection tracking identifies as invalid. After that, we put i