add action=masquerade chain=srcnat ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat disabled=no dst-port=1194 in-interface=ether1-WAN protocol=udp to-addresses=192.168.1.17
/ip firewall filter
add action=accept chain=forward dst-address=77.78.97.220 dst-port=443 \
in-bridge-port="E1-CASA uplink" out-bridge-port=E2-SERVER \
packet-mark=GEO_OK protocol=tcp