Reasoning behind in/out/fwd netfilter rules

See discussion here for more detail

To actually drop traffic you can use our network acl feature.