/ip firewall filter add action=accept chain=input dst-port=8291 in-interface="PPoE | CeskyBezdrat" protocol=tcp add action=accept chain=input in-interface="PPoE | CeskyBezdrat" protocol=udp src-port=500,4500,1701 add action=accept chain=forward dst-port=22,25,465,587,143,993,110,995,4190,80 in-interface="PPoE | CeskyBezdrat" protocol=tcp add action=accept chain=forward dst-port=443 in-interface="PPoE | CeskyBezdrat" protocol=tcp add action=accept chain=forward comment=Proxmox dst-port=8006 in-interface= "PPoE | CeskyBezdrat" protocol=tcp add action=accept chain=input in-interface="PPoE | CeskyBezdrat" protocol= ipsec-esp add action=accept chain=input in-interface="PPoE | CeskyBezdrat" protocol= ipsec-ah add action=drop chain=input dst-port=53 in-interface="PPoE | CeskyBezdrat" protocol=udp /ip firewall nat add action=masquerade chain=srcnat out-interface="PPoE | CeskyBezdrat" add action=dst-nat chain=dstnat dst-address=84.19.76.30 dst-port=443 protocol= tcp to-addresses=10.10.20.4 to-ports=443 add action=dst-nat chain=dstnat dst-address=84.19.76.30 dst-port=80 protocol= tcp to-addresses=10.10.20.4 to-ports=80