$ 0 0 I'd go for:guest_in: default-acceptallow estab/relateddrop invalid accept dest 10.1.1.1/24 drop dest rfc1918