Always reject “i/o/f” on “General Settings”.
Always reject “forward” on “Zones”. Only one subnet will be there anyway.
Input is for accessing the router.
No need to configure “forward” as we put fireward zones to forward on “Zone Forwarding”.