$ 0 0 Protect lans firewall...Default allowRule1 drop destination 10.0.0.0/8Goes on every lan_in rule