Hello CiscoGuy!

I am no expert and do not claim this to be best practice but what I have configured on our firewalls is as follows (these rules are located just above the cleanup).

Source:any...