39 ;;; defconf: accept established,related,untracked
chain=input action=accept connection-state=established,related,untracked log=no
log-prefix=""
40 ;;; defconf: accept ICMP
chain=input action=accept protocol=icmp in-interface=ether1 limit=5,5:packet log=no
log-prefix=""
41 ;;; defconf: accept ICMP
chain=forward action=accept protocol=icmp in-interface=ether1 limit=5,5:packet
log=no log-prefix=""
42 ;;; defconf: drop all not coming from LAN
chain=input action=drop in-interface=ether1 log=no log-prefix=""
43 ;;; defconf: accept in ipsec policy
chain=forward action=accept log=no log-prefix="" ipsec-policy=in,ipsec
44 ;;; defconf: accept out ipsec policy
chain=forward action=accept log=no log-prefix="" ipsec-policy=out,ipsec
45 ;;; defconf: accept established,related, untracked
chain=forward action=accept connection-state=established,related,untracked log=no
log-prefix=""
46 ;;; defconf: drop all from WAN not DSTNATed
chain=forward action=drop connection-state="" connection-nat-state=!dstnat
in-interface=ether1 log=no log-prefix=""