An additional difference is the final rule which drops all new connection tries with the WAN port to our LAN network (Except DstNat is utilised). Without having this rule, if an attacker understands or guesses your neighborhood subnet, he/she will build connections on to nearby hosts and induce a protection https://wbofficial.com