The default firewall state for IPv4 and IPv6 would be enabled. This can be disabled via the AAISP control pages. Rules can be added as required.
The firewall is configured via the router's Web interface:
Security -> Firewall -> Access Control
You don't need to create any special 'protocol' lists, you can simply enter in the Target IP/Port etc. in to the rule.
From the CLI the 'iptables' command is available, which is familiar to Linux users.