I never had to set such rules, I believe this is the default:
vyos@router01:~$ show firewall
Firewall Global Settings
Firewall state-policy for all IPv4 and Ipv6 traffic
state action log
invalid drop disabled
established accept disabled
related accept disabled