Vyzkoušej:
/ip firewall filter \
add action=accept chain=forward comment="" disabled=no dst-port=3389 \
in-interface=<ROZHRANÍ.DO.NETU> protocol=tcp
/ip firewall nat \
add action=netmap chain=dstnat comment="" disabled=no dst-address=<VEŘEJNÁ.IP> dst-port=3389 \
in-interface=<ROZHRANÍ.DO.NETU> protocol=tcp to-addresses=192.168.0.2