Another difference is the final rule which drops all new link makes an attempt within the WAN port to our LAN community (Until DstNat is utilized). With out this rule, if an attacker is aware of or guesses your local subnet, he/she will be able to build connections directly to https://wbofficial.com