+
+if [ -d /etc/firewall.d ]; then
+ for fw in /etc/firewall.d/??*; do
+ [ -x $fw ] && $fw
+ done
+fi
+
+# defaults
+
+$IPT -t filter -A INPUT -p icmp -j ACCEPT
+$IPT -t filter -A INPUT -p 47 -j ACCEPT # allow GRE
+$IPT -t filter -A INPUT -i $WAN -p tcp --syn --tcp-option \! 2 -j DROP
+$IPT -t filter -A INPUT -i $WAN -p tcp -j REJECT --reject-with tcp-reset
+$IPT -t filter -A INPUT -i $WAN -j REJECT --reject-with icmp-port-unreachable
+
+$IPT -t filter -A FORWARD -i br0 -o br0 -j ACCEPT
+$IPT -t filter -A FORWARD -i $WAN -m state --state NEW -j DROP