When the default policy for the netfilter INPUT chain is set to DROP, why should a rule allowing traffic to localhost exist?