/ip firewall filter
add action=accept chain=input comment=IN-SSH-Allow connection-state=new dst-port=5222 protocol=tcp
add action=accept chain=input comment=IN-Winbox-Allow connection-state=new dst-port=58291 protocol=tcp
add action=accept chain=input comment=IN-DNS-from-LAN-Allow dst-port=53 protocol=udp src-address=192.168.0.0/24
add action=accept chain=input comment=IN-Web-from-LAN-Allow connection-state=new dst-port=80 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=input comment=IN-EST-REL-Allow connection-state=established,related
add action=drop chain=input comment=IN-ALL-Drop
add action=fasttrack-connection chain=forward comment=Enable-Fasttrack src-address=192.168.0.0/24