/ip firewall address-list add address=10.0.0.0/8 list=ACCEPT
    /ip firewall address-list add address=192.168.0.0/16 list=ACCEPT
    /ip firewall address-list add address=5.188.129.176/29 list=ACCEPT
    /ip firewall filter add action=passthrough chain=unused-hs-chain comment="place hotspot rules here" disabled=yes
    /ip firewall filter add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
    /ip firewall filter add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
    /ip firewall filter add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
    /ip firewall filter add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
    /ip firewall filter add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN src-address-list=!ACCEPT
    /ip firewall filter add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
    /ip firewall filter add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
    /ip firewall filter add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
    /ip firewall filter add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
    /ip firewall filter add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
    /ip firewall filter add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
    Дата публикации: 07 сентября 2024 года