mi dicono:
Your router accepts any traffic from already established connections, This mostly means that it is allowed to connect to the world, but any other traffic from your isp is dropped
that are the 2 rules in the INPUT chain that cause that
You forward also any traffic that already has a connection established and drop any unrelated traffic from outside
the first rule in the forward chain is to make sure that the packets send to your isp are not too large
you can read about that here:
http://lartc.org/howto/lartc.cookbook.mtu-mss.html
and it filters icmp traffic to outside of the type destination unreachable and icmp traffic that should not be there (The invalid state)