There is one thing I'm wondering. Well, just now.
The "drop invalid" rule.
Many configuration put this rule as a second or third rule in the chain. Usually first rule is "accept established,related,untracked".
I understand these rules work in order, first rule, second rule and so on.
Now, first rule "accept established,related,untracked" let traffic flow if traffic is "established,related,untracked". And firewall does not check following rules anymore?
What if this traffic "established,related,untracked" contain something "invalid"? Is it checked by firewall at all?
Should "drop invalid" be the first rule?
Another thing, does this "drop invalid" really need all this: viewtopic.php?t=83387 ? (How to ***really*** block invalid ICMP, TCP, UDP packets and others (ver. 2021))