I found this article.
Is this any helpfull or necessary ?

Also I thought ipset was already in openwrt

There's already a firewall in OpenWRT ?
If you don't know why you'd need it, you probably don't.

In the default firewall settings, unsolicited packets from WAN are already rejected. Changing from REJECT to DROP is OK.

If you open ports for other internet-exposed services (VPN, port forwarding), you can use the popular banip package instead of the outdated script in the article.

