/ip firewall filter add action=accept chain=input comment=”accept established, related, untracked” connection-state=established,related,untracked /ip firewall filter add action=drop chain=input comment=”drop invalid” connection-state=invalid /ip firewall filter add action=accept chain=input comment=”accept normal ping from anywhere (type 8 code 0)” icmp-options=8:0 protocol=icmp