/ip firewall filter add action=accept chain=input comment=»accept established, related, untracked» connection-state=established,related,untracked /ip firewall filter add action=drop chain=input comment=»drop invalid» connection-state=invalid /ip firewall filter add action=accept chain=input comment=»accept normal ping from anywhere (type 8 code 0)» icmp-options=8:0 protocol=icmp