add action=masquerade chain=srcnat ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat disabled=no dst-port=1194 in-interface=ether1-WAN protocol=udp to-addresses=192.168.1.17
/ip firewall filter
add action=accept chain=forward dst-address=77.78.97.220 dst-port=443 \
in-bridge-port="E1-CASA uplink" out-bridge-port=E2-SERVER \
packet-mark=GEO_OK protocol=tcp
/ip firewall nat
add action=dst-nat chain=dstnat dst-port=3389 protocol=tcp src-mac-address=52:54:00:34:3A:70 to-addresses=192.168.88.203
/ip firewall nat
add action=dst-nat chain=dstnat dst-port=3389 protocol=tcp src-address-list="IP ALLOW" to-addresses=192.168.88.203
/ip firewall address-list
add address=216.17.43.160 comment="one ip" list="IP ALLOW"