/ip firewall filter add action=accept chain=forward connection-state=established,related add action=accept chain=forward in-interface=br_lan out-interface=ether1 src-address=172.25.100.0/24 add action=accept chain=forward connection-nat-state=dstnat add action=drop chain=forward add action=accept chain=output add action=accept chain=input connection-state=established,related add action=accept chain=input icmp-options=8:0 protocol=icmp add action=accept chain=input icmp-options=3:4 protocol=icmp add action=accept chain=input connection-state=new dst-address=172.25.100.1 dst-port=53 in-interface=br_lan protocol=udp src-address=172.25.100.0/24 add action=accept chain=input connection-state=new dst-address=172.25.100.1 dst-port=8291 in-interface=br_lan protocol=tcp src-address=172.25.100.0/24 add action=drop chain=input