Although the firewall shields the router from the general public interface, you may still need to disable RouterOS expert services.The very first rule accepts packets from currently recognized connections, assuming they are Risk-free not to overload the CPU. The second rule drops any packet that link monitoring identifies as invalid. Following that