chain input {
type filter hook input priority filter; policy drop;
ip protocol icmp accept
ip saddr
10.10.0.0/24 ip daddr
0.0.0.0/0 accept
tcp dport { 22, 56, 80, 81, 443, 1194, 8080 } accept
udp dport { 56, 1194 } accept
ip daddr
127.0.0.0/8 accept
ip daddr
127.0.0.53 accept
ip daddr
127.0.0.0/8 accept
udp dport 53 accept
tcp dport 53 accept
}