Even though the firewall safeguards the router from the public interface, you should still need to disable RouterOS solutions.The initial rule accepts packets from previously founded connections, assuming They are really Protected not to overload the CPU. The 2nd rule drops any packet that link tracking identifies as invalid. After that, we setup u