Thanks @ColinTaylor that seems to work like a charm.
three questions
1.
For TCP there are several categories. SYN, ACK, FIN, RST, URG, PSH
Should I DROP all of them?
The ALL target seems not to work?
2.
I don't really understand the difference between iptables -I and -A i.e Insert and...