/ip firewall filter
add chain=input comment="default configuration" protocol=icmp
add chain=input dst-port=61001 in-interface=WAN protocol=tcp
add chain=input dst-port=161 in-interface=WAN protocol=udp
add chain=input comment="default configuration" connection-state=established
add chain=input comment="default configuration" connection-state=related
add action=drop chain=input comment="default configuration" in-interface=WAN
add action=drop chain=input comment="default configuration" in-interface=\ sfp1-gateway
add chain=forward comment="default configuration" connection-state=\ established
add chain=forward comment="default configuration" connection-state=related
add action=drop chain=forward comment="default configuration" \ connection-state=invalid
/ip firewall nat
add action=masquerade chain=srcnat comment="default configuration" disabled=\ yes out-interface=sfp1-gateway to-addresses=0.0.0.0
add action=masquerade chain=srcnat disabled=yes dst-address=192.168.1.3 \ dst-port=80 out-interface=LAN protocol=tcp src-address=192.168.1.0/24
add action=masquerade chain=srcnat disabled=yes dst-address=192.168.1.3 \ dst-port=25 out-interface=LAN protocol=tcp src-address=192.168.1.0/24
add action=dst-nat chain=dstnat disabled=yes dst-address=1.1.1.1 \ protocol=tcp src-address=192.168.1.0/24 to-addresses=192.168.1.3
add action=masquerade chain=srcnat disabled=yes dst-address=192.168.1.3 \ dst-port=80 out-interface=LAN protocol=tcp src-address=192.168.1.0/24
add action=dst-nat chain=dstnat dst-address=1.1.1.1 protocol=tcp \ to-addresses=192.168.1.3
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=10000 \ protocol=tcp to-addresses=192.168.1.3 to-ports=10000
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=3306 \ protocol=tcp to-addresses=192.168.1.3 to-ports=3306
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=21 \ protocol=tcp to-addresses=192.168.1.3 to-ports=21
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=25 \ protocol=tcp to-addresses=192.168.1.3 to-ports=25
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=110 \ protocol=tcp to-addresses=192.168.1.3 to-ports=110
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=143 \ protocol=tcp to-addresses=192.168.1.3 to-ports=143
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=443 \ protocol=tcp to-addresses=192.168.1.3 to-ports=443
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=22 \ protocol=tcp to-addresses=192.168.1.3 to-ports=61001
add action=dst-nat chain=dstnat dst-address=1.1.1.1 dst-port=22 \ protocol=tcp to-addresses=192.168.1.3 to-ports=22
add action=masquerade chain=srcnat comment="default configuration" \ out-interface=WAN