I had my input chain to block everything apart from clients on my main VLAN - Similar to the securing your router wiki page. I have noticed that clients from other VLANS try to access the router using ports such as 67,68 (DHCP), NETBIOS related and various other ports like 37942, 59838, 57621 the list goes on. DHCP works fine despite this.
At the moment I have locked things down further to only allow my admin PC and second Mikrotik to have input chain access, and hence even more entries shown in the log.
Should I allow all LAN clients access as per the wiki page or just allow admin machines?
Should I be allowing certain ports e.g. 67,68