Tks @R4kk00n... been solved by following your tip: @toddnat, you can also try to use an ugly hack with source NAT'ting your outgoing BFD packets. It goes something like this (I'm writing from memory, so there might be errors): /ip firewall nat add chain=src-nat action=srcnat src-address-type=local p...