Although the firewall guards the router from the public interface, you should still choose to disable RouterOS solutions.The initial rule accepts packets from currently established connections, assuming They are really safe not to overload the CPU. The next rule drops any packet that link monitoring identifies as invalid. After that, we create norm