Okay...tq b4 Mr.Cibernet and Mr.Raulborda
I think my question not connect with the answer...
Maybe cause my english to mussy
But...pleasing 4 me coz I've found the "rule"
I put this script and ..yeah...walking matching with the one which I wish
[admin@Gw] ip firewall filter> pr
Flags: X - disabled, I - invalid, D - dynamic
0 chain=forward in-interface=eth1 out-interface=eth0 src-address=xxx.xxx.xxx.xxx action=accept
1 chain=forward connection-state=established action=accept
2 chain=forward connection-state=related action=accept
3 chain=input connection-state=established action=accept
4 chain=input connection-state=related action=accept
5 chain=forward protocol=icmp action=accept
6 chain=forward connection-state=invalid action=drop
7 chain=forward action=drop
With that script, client where connect to router can access internet but can't access from internet ....
So their IP although "Public" but can't be a server....
Tq and tq again
With respon all of you I become to motivated