屏蔽外网连接 ,有需要访问内网就用端口映射

/ip firewall filteradd action=accept chain=input connection-state=established,related \    in-interface-list=wanadd action=drop chain=input connection-state=invalid in-interface-list=wanadd action=drop chain=input in-interface-list=wan log=