add action=masquerade chain=srcnat comment=Masquerade out-interface=pppoe-out1
А вот это зачем?
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 10.73.***.*** 0
1 ADC 10.73.***.****/32 46.147.***.*** pppoe-out1 0
2 A S 192.168.0.0/24 pptp-out-msk 1
3 ADC 192.168.1.0/24 192.168.1.1 rov.local.bridge 0
4 ADC 192.168.200.1/32 192.168.200.2 pptp-out-msk 0
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 10.73.***.** 0
1 ADC 10.73.***.**/32 46.147.**.*** pppoe-out1 0
2 A S 192.168.0.0/24 192.168.200.1 1
3 ADC 192.168.1.0/24 192.168.1.1 rov.local.bridge 0
4 ADC 192.168.200.1/32 192.168.200.2 pptp-out-msk 0
/ip firewall filter
add chain=input comment="accept remote winbox" disabled=yes in-interface=ether1-WAN port=8291,80 protocol=tcp
add chain=input in-interface=<pptp-pptp_rov-1> protocol=icmp
/ip firewall filter
# INPUT
add chain=input connection-state=invalid action=drop comment="drop invalid connections"
add chain=input connection-state=related action=accept comment="allow related connections"
add chain=input connection-state=established action=accept comment="allow established connections"
# ext input
# local input
add chain=input src-address=192.168.0.1/24 action=accept in-interface=!ether1-WAN
# drop all other input
add chain=input action=drop comment="drop everything else"
# OUTPUT
add chain=output action=accept out-interface=ether1-WAN comment="accept everything to internet"
add chain=output action=accept out-interface=!ether1-WAN comment="accept everything to non internet"
add chain=output action=accept comment="accept everything"
# FORWARD
add chain=forward connection-state=invalid action=drop comment="drop invalid connections"
add chain=forward connection-state=established action=accept comment="allow already established connections"
add chain=forward connection-state=related action=accept comment="allow related connections"
add chain=forward src-address=0.0.0.0/8 action=drop
add chain=forward dst-address=0.0.0.0/8 action=drop
add chain=forward src-address=127.0.0.0/8 action=drop
add chain=forward dst-address=127.0.0.0/8 action=drop
add chain=forward src-address=224.0.0.0/3 action=drop
add chain=forward dst-address=224.0.0.0/3 action=drop
# (1) jumping
add chain=forward protocol=tcp action=jump jump-target=tcp
add chain=forward protocol=udp action=jump jump-target=udp
add chain=forward protocol=icmp action=jump jump-target=icmp
# (3) accept forward from local to internet
add chain=forward action=accept in-interface=!ether1-WAN out-interface=ether1-gateway \
comment="accept from local to internet"
# (4) drop all other forward
add chain=forward action=drop comment="drop everything else"
# (2) deny some types common types
add chain=tcp protocol=tcp dst-port=69 action=drop comment="deny TFTP"
add chain=tcp protocol=tcp dst-port=111 action=drop comment="deny RPC portmapper"
add chain=tcp protocol=tcp dst-port=135 action=drop comment="deny RPC portmapper"
add chain=tcp protocol=tcp dst-port=137-139 action=drop comment="deny NBT"
add chain=tcp protocol=tcp dst-port=445 action=drop comment="deny cifs"
add chain=tcp protocol=tcp dst-port=2049 action=drop comment="deny NFS"
add chain=tcp protocol=tcp dst-port=12345-12346 action=drop comment="deny NetBus"
add chain=tcp protocol=tcp dst-port=20034 action=drop comment="deny NetBus"
add chain=tcp protocol=tcp dst-port=3133 action=drop comment="deny BackOriffice"
add chain=tcp protocol=tcp dst-port=67-68 action=drop comment="deny DHCP"
add chain=udp protocol=udp dst-port=69 action=drop comment="deny TFTP"
add chain=udp protocol=udp dst-port=111 action=drop comment="deny PRC portmapper"
add chain=udp protocol=udp dst-port=135 action=drop comment="deny PRC portmapper"
add chain=udp protocol=udp dst-port=137-139 action=drop comment="deny NBT"
add chain=udp protocol=udp dst-port=2049 action=drop comment="deny NFS"
add chain=udp protocol=udp dst-port=3133 action=drop comment="deny BackOriffice"
add chain=icmp protocol=icmp icmp-options=0:0 action=accept comment="echo reply"
add chain=icmp protocol=icmp icmp-options=3:0 action=accept comment="net unreachable"
add chain=icmp protocol=icmp icmp-options=3:1 action=accept comment="host unreachable"
add chain=icmp protocol=icmp icmp-options=3:4 action=accept comment="host unreachable fragmentation required"
add chain=icmp protocol=icmp icmp-options=4:0 action=accept comment="allow source quench"
add chain=icmp protocol=icmp icmp-options=8:0 action=accept comment="allow echo request"
add chain=icmp protocol=icmp icmp-options=11:0 action=accept comment="allow time exceed"
add chain=icmp protocol=icmp icmp-options=12:0 action=accept comment="allow parameter bad"
add chain=icmp action=drop comment="deny all other types"
# (5) drop all other forward
add chain=forward action=drop comment="drop (2) everything else"
0 D chain=forward action=change-mss new-mss=1410 passthrough=yes tcp-flags=syn protocol=tcp out-interface=all-ppp tcp-mss=1411-65535
log=no log-prefix=""
1 D chain=forward action=change-mss new-mss=1360 passthrough=yes tcp-flags=syn protocol=tcp in-interface=all-ppp tcp-mss=1361-65535 log=no
log-prefix=""
add action=masquerade chain=srcnat comment=wan src-address=192.168.0.0/24
add action=masquerade chain=srcnat comment=wan src-address=192.168.2.0/24
/ip firewall filter
add chain=input comment="accept remote winbox" disabled=yes in-interface=ether1-WAN port=8291,80 protocol=tc
add chain=input in-interface=<pptp-pptp_rov-1>
add chain=input comment="accept PPTP tunels" dst-port=1723 protocol=tcp
add chain=input protocol=gre
add chain=input comment="accept l2tp tunels" port=1701,500,4500 protocol=udp
add chain=input protocol=ipsec-esp
add action=drop chain=input comment="drop invalid connections" connection-state=invalid
add chain=input comment="allow related connections" connection-state=related
add chain=input comment="allow established connections" connection-state=established
add chain=input in-interface=!ether1-WAN src-address=192.168.0.0/24
add chain=output comment="accept everything to internet" out-interface=ether1-WAN
add chain=output comment="accept everything to non internet" out-interface=!ether1-WAN
add chain=output comment="accept everything"
add action=drop chain=forward comment="drop invalid connections" connection-state=invalid
add chain=forward comment="allow already established connections" connection-state=established
add chain=forward comment="allow related connections" connection-state=related
add action=drop chain=forward src-address=0.0.0.0/8
add action=drop chain=forward dst-address=0.0.0.0/8
add action=drop chain=forward src-address=127.0.0.0/8
add action=drop chain=forward dst-address=127.0.0.0/8
add action=drop chain=forward src-address=224.0.0.0/3
add action=drop chain=forward dst-address=224.0.0.0/3
add action=jump chain=forward jump-target=tcp protocol=tcp
add action=jump chain=forward jump-target=udp protocol=udp
add action=jump chain=forward jump-target=icmp protocol=icmp
add action=drop chain=input comment="drop everything else"
/ip firewall nat
add action=masquerade chain=srcnat comment=wan src-address=192.168.0.0/24
add action=masquerade chain=srcnat comment=Masquerade disabled=yes out-interface=ether1-WAN
/ip firewall filter
add chain=input comment="accept remote Winbox" in-interface=pppoe-out1 port=8291 protocol=tcp
add chain=output comment="accept everything to internet" out-interface=ether1-WAN
add chain=output comment="accept everything to non internet" out-interface=!ether1-WAN
add chain=output comment="accept everything"
add action=drop chain=forward comment="drop invalid connections" connection-state=invalid
add chain=forward comment="allow already established connections" connection-state=established
add chain=forward comment="allow related connections" connection-state=related
add action=drop chain=forward src-address=0.0.0.0/8
add action=drop chain=forward dst-address=0.0.0.0/8
add action=drop chain=forward src-address=127.0.0.0/8
add action=drop chain=forward dst-address=127.0.0.0/8
add action=drop chain=forward src-address=224.0.0.0/3
add action=drop chain=forward dst-address=224.0.0.0/3
add action=jump chain=forward jump-target=tcp protocol=tcp
add action=jump chain=forward jump-target=udp protocol=udp
add action=jump chain=forward jump-target=icmp protocol=icmp
add chain=input protocol=icmp
add chain=input connection-state=established
add chain=input connection-state=related
add action=drop chain=input in-interface=pppoe-out1
/ip firewall nat
add action=masquerade chain=srcnat comment=wan src-address=192.168.2.0/24
add action=masquerade chain=srcnat comment=Masquerade disabled=yes out-interface=pppoe-out1
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 A S 0.0.0.0/0 188.64.***.* 1
1 ADC 188.64.***.*/24 188.64.***.** ether1-WAN 0
2 ADC 192.168.0.0/24 192.168.0.1 dm.local.bridge 0
3 ADC 192.168.0.171/32 192.168.0.93 <l2tp-krr.offic... 0
4 ADC 192.168.0.173/32 192.168.0.33 <l2tp-loginova-1> 0
5 A S 192.168.1.0/24 192.168.200.2 1
6 A S 192.168.2.0/24 192.168.200.3 1
7 S 192.168.3.0/24 pptp-in-zdorovie 1
8 A S 192.168.11.0/24 pptp-out-kemerovo 1
9 ADC 192.168.20.30/32 192.168.20.31 pptp-out-kemerovo 0
10 ADC 192.168.200.2/32 192.168.200.1 <pptp-pptp_krr> 0
11 ADC 192.168.200.3/32 192.168.200.1 <pptp-pptp_rov-1> 0
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 10.73.***.** 0
1 ADC 10.73.***.**/32 46.147.**.*** pppoe-out1 0
2 A S 192.168.0.0/24 192.168.200.1 1
3 ADC 192.168.2.0/24 192.168.2.1 rov.local.bridge 0
4 ADC 192.168.200.1/32 192.168.200.3 pptp-out-msk 0