To block inbound access from public IP´s, create a DNAT rule to a non-existing destination.
Traffic from: create a list of public IP´s you want to block
Service: Any
Going to: your WAN Address
Destination: a non-existing host (example. 169.0.0.1)