add action=accept chain=input comment="Allow established & related connections" connection-state=established,related,untracked
add action=drop chain=input comment="Drop invalid connections" connection-state=invalid
add action=accept chain=input comment="Allow ping" protocol=icmp
add action=accept chain=input comment="Allow Winbox" dst-port=8291 protocol=tcp
add action=accept chain=input comment="Allow DNS" dst-port=53 in-interface-list=!ISP protocol=udp
add action=drop chain=input comment="Drop other connections"
add action=accept chain=forward comment="Allow established & related forward connections" connection-state=established,related
add action=drop chain=forward comment="Drop invalid connections" connection-state=invalid
add action=drop chain=forward comment="Drop All connections except NAT to WAN interface" connection-nat-state=!dstnat in-interface-list=ISP