add action=accept chain=forward out-interface=eth1-Sunlink src-address=192.168.60.13
add action=accept chain=forward dst-address=192.168.60.1 src-address=192.168.60.13
add action=reject chain=forward dst-address=192.168.60.0/24 reject-with=icmp-network-unreachable src-address=192.168.60.13
add action=accept chain=forward comment="accpet establishment" connection-state=established
add action=accept chain=input connection-state=established
add action=accept chain=forward comment="accept related" connection-state=related
add action=accept chain=input connection-state=related
add action=accept chain=input comment="l2tp port" dst-port=1701 protocol=udp
add action=drop chain=forward comment="drop invalid" connection-state=invalid
add action=drop chain=input connection-state=invalid
add action=drop chain=input comment="denny all" in-interface=eth1-Sunlink
add action=drop chain=forward in-interface=eth1-Sunlink
NAT
add action=masquerade chain=srcnat out-interface=eth1-Sunlink
[admin@MikroTik] > /ip route oute add dst-address=0.0.0.0/0 gateway=172.16.0.7 routing-mar=RT
bad command name oute (line 1 column 11)
[admin@MikroTik] >> /ip route out add dst-address=0.0.0.0/0 gateway=172.16.0.7 routing-mar=RT
bad command name out (line 1 column 11)
[admin@MikroTik] >> /ip route
cache nexthop rule vrf add check comment disable edit enable export find print remove set unset
скопировал с Как направить весь трафик кроме локального через WIREGUARD? :)