Dynamic tackle configuration is the easiest possibility. Only put in place a DHCP client on the public interface.The primary rule accepts packets from previously proven connections, assuming They may be Protected to not overload the CPU. The 2nd rule drops any packet that relationship tracking identifies as invalid. After that, we set up usual ackn