/ip firewall filter
add chain=input action=drop connection-state=invalid comment="Drop invalid"
add chain=input action=accept connection-state=established,related,untracked comment="Accept established/related/untracked"
add chain=input action=accept in-interface-list=LAN_Trusted_Interfaces comment="Allow LAN management"
add chain=input action=accept dst-address=127.0.0.1 comment="Allow loopback"
add chain=input action=accept ipsec-policy=in,ipsec comment="Allow IPsec in"
add chain=input action=drop in-interface-list=!LAN comment="Drop all not from LAN"
/ip firewall filter
add chain=forward action=drop connection-state=invalid comment="Drop invalid"
add chain=forward action=fasttrack-connection hw-offload=yes connection-state=established,related comment="Fasttrack established/related"
add chain=forward action=accept connection-state=established,related,untracked comment="Accept established/related/untracked"
add chain=forward action=accept ipsec-policy=in,ipsec comment="Allow IPsec in"
add chain=forward action=accept ipsec-policy=out,ipsec comment="Allow IPsec out"
add chain=forward action=drop connection-state=new connection-nat-state=!dstnat in-interface-list=WAN comment="Drop all from WAN not dstnat"