/ip firewall filter
add action=accept chain=input comment=Lan_WiFi_Accept in-interface-list=LAN
add action=accept chain=input comment=\
Related_Established_untracked_Wan_Accept connection-state=\
established,related,untracked
add action=accept chain=input comment="DNS only Lan & Vlan" dst-port=53 \
in-interface-list=!Internet protocol=udp
add action=accept chain=input comment=WinBox dst-port=7297,443,3389 \
log-prefix="_____________ 7297---------" protocol=tcp
add action=drop chain=input comment="Ping_Drop_ICMP_IN echo request" \
icmp-options=0:0-255 in-interface-list=!LAN protocol=icmp
add action=accept chain=input comment="For VPN" dst-port=500,1701,4500 \
in-interface-list=Internet protocol=udp
add action=accept chain=input comment="For VPN" in-interface-list=Internet \
protocol=ipsec-esp
add action=accept chain=input comment=Allow_limited_pings_ICMP protocol=icmp
add action=drop chain=input comment=Drop_all_invalid connection-state=invalid
add action=drop chain=input comment=Bogon_Wan_Drop in-interface-list=Internet \
src-address-list=BOGON