Thank you Jeff and MK24,
the router is used to link 2 local network, one is the local network (router's WAN port) and the other is a local network ( router's LAN ports) inside an industrial equipment.
root@OpenWrt:~# lsmod
cfg80211 202032 5 rt2x00lib,mt76x2e,mt7603e,mt76,mac80211
compat 544 4 rt2800soc,rt2800pci,mac80211,cfg80211
crc_ccitt 960 2 rt2800lib,ppp_async
crc_itu_t 960 0
eeprom_93cx6 1984 1 rt2800pci
ehci_hcd 32912 1 ehci_platform
ehci_platform 4384 0
gpio_button_hotplug 6176 0
ip_tables 10096 3 iptable_nat,iptable_mangle,iptable_filter
ip6_tables 9856 2 ip6table_mangle,ip6table_filter
ip6t_REJECT 896 2
ip6table_filter 608 1
ip6table_mangle 1088 1
ipt_MASQUERADE 640 1
ipt_REJECT 864 2
iptable_filter 608 1
iptable_mangle 832 1
iptable_nat 672 1
leds_gpio 2752 0
mac80211 390272 7 rt2800lib,rt2x00soc,rt2x00pci,rt2x00lib,mt76x2e,mt7603e,mt76
mmc_block 20496 0
mmc_core 74688 2 mmc_block,mtk_sd
mt76 18880 2 mt76x2e,mt7603e
mt7603e 28288 0
mt76x2e 42944 0
mtk_sd 19024 0
nf_conntrack 55488 15 nf_nat_ftp,nf_conntrack_ftp,nf_conntrack_ipv6,ipt_MASQUERADE,xt_state,xt_nat,xt_conntrack,xt_REDIRECT,xt_CT,nf_nat_masquerade_ipv4,nf_conntrack_ipv4,nf_nat_ipv4,nf_nat,nf_flow_table,nf_conntrack_rtcache
nf_conntrack_ftp 5152 1 nf_nat_ftp
nf_conntrack_ipv4 4928 24
nf_conntrack_ipv6 5040 6
nf_conntrack_rtcache 2432 0
nf_defrag_ipv4 1024 1 nf_conntrack_ipv4
nf_defrag_ipv6 8944 1 nf_conntrack_ipv6
nf_flow_table 12176 2 xt_FLOWOFFLOAD,nf_flow_table_hw
nf_flow_table_hw 1984 1
nf_log_common 2624 2 nf_log_ipv4,nf_log_ipv6
nf_log_ipv4 3232 0
nf_log_ipv6 3360 0
nf_nat 9360 5 nf_nat_ftp,xt_nat,nf_nat_redirect,nf_nat_masquerade_ipv4,nf_nat_ipv4
nf_nat_ftp 1184 0
nf_nat_ipv4 3760 1 iptable_nat
nf_nat_masquerade_ipv4 1392 1 ipt_MASQUERADE
nf_nat_redirect 1088 1 xt_REDIRECT
nf_reject_ipv4 2048 1 ipt_REJECT
nf_reject_ipv6 2464 1 ip6t_REJECT
nls_base 4736 1 usbcore
ohci_hcd 22480 1 ohci_platform
ohci_platform 3936 0
ppp_async 6176 0
ppp_generic 21104 3 pppoe,ppp_async,pppox
pppoe 8032 0
pppox 1168 1 pppoe
rt2800lib 86624 3 rt2800soc,rt2800pci,rt2800mmio
rt2800mmio 5376 2 rt2800soc,rt2800pci
rt2800pci 3568 0
rt2800soc 2384 0
rt2x00lib 31120 7 rt2800soc,rt2800pci,rt2800mmio,rt2800lib,rt2x00soc,rt2x00pci,rt2x00mmio
rt2x00mmio 2144 3 rt2800soc,rt2800pci,rt2800mmio
rt2x00pci 1568 1 rt2800pci
rt2x00soc 1120 1 rt2800soc
slhc 4224 1 ppp_generic
usb_common 2176 1 usbcore
usbcore 119376 4 ohci_platform,ohci_hcd,ehci_platform,ehci_hcd
x_tables 12240 24 ipt_REJECT,ipt_MASQUERADE,xt_time,xt_tcpudp,xt_state,xt_nat,xt_multiport,xt_mark,xt_mac,xt_limit,xt_conntrack,xt_comment,xt_TCPMSS,xt_REDIRECT,xt_LOG,xt_FLOWOFFLOAD,xt_CT,iptable_mangle,iptable_filter,ip_tables,ip6t_REJECT,ip6table_mangle,ip6table_filter,ip6_tables
xt_CT 2496 0
xt_FLOWOFFLOAD 2608 0
xt_LOG 736 0
xt_REDIRECT 672 0
xt_TCPMSS 2688 2
xt_comment 448118
xt_conntrack 2176 16
xt_limit 960 18
xt_mac 576 0
xt_mark 640 0
xt_multiport 1184 0
xt_nat 1504 12
xt_state 672 0
xt_tcpudp 1728 16
xt_time 1568 0
Firewall settings
root@OpenWrt:~# cat /etc/config/firewall
config defaults
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option network 'lan'
config zone
option name 'wan'
option output 'ACCEPT'
option network 'wan'
option input 'ACCEPT'
option forward 'ACCEPT'
option masq '1'
option mtu_fix '1'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fc00::/6'
option dest_ip 'fc00::/6'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
option enabled '0'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
option enabled '0'
config include
option path '/etc/firewall.user'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option dest_ip '169.254.5.20'
option dest_port '21'
option name 'FTP'
option src_dport '21'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option dest_ip '169.254.5.20'
option dest_port '20'
option name 'ftp attivo'
option src_dport '20'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option src_dport '2122'
option dest_ip '169.254.5.20'
option dest_port '2122'
option name 'ftp data'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp'
option src_dport '2121'
option dest_ip '169.254.5.20'
option dest_port '2121'
option name 'ftp data2'