Cumberbatch
А выведите эти правила через
/ip firewall filter export
/ip firewall filter
add action=fasttrack-connection chain=forward connection-state=\
established,related
add action=accept chain=input comment=gre in-interface-list=Internet \
log-prefix=666666666 protocol=gre
add action=accept chain=input comment="established and related connections" \
connection-state=established,related
add action=accept chain=forward connection-state=established,related
add action=accept chain=input comment="l2tp, ipsec" dst-port=1701,500,4500 \
in-interface-list=Internet protocol=udp tcp-flags=""
add action=accept chain=input in-interface-list=Internet ipsec-policy=\
in,ipsec protocol=ipsec-esp
add action=accept chain=input in-interface-list=Internet ipsec-policy=\
in,ipsec protocol=ipsec-ah
add action=drop chain=input comment="invalid connections" connection-state=\
invalid in-interface-list=Internet log-prefix=8888888
add action=drop chain=forward connection-state=invalid in-interface-list=\
Internet