According to Routed Client [Old OpenWrt Wiki]

masquerading is necessary for NAT so that is why WAN has to enable masquerading.

Don’t enable ACCEPT in WAN. If you enable ACCEPT, it means the router can accept connection from the WAN, e.g. 22 or samba. That means all port is opened in WAN and your router is under serious risk.

Think about the “wanna cry” virus this week. It will try to use samba port and spread itself. While if you have a router above your PC, you should not be affected.