Thanks, your reply and BranoB's link are making things clearer.
So I could keep that ruleset as is, for WAN-in, and then have another ruleset for WAN-out, to control what the ruleset for WAN-in, accepts back in?
Image may be NSFW.
Clik here to view.