Dmitry on firewalling ip firewall mangle

Hi,
i used this guide http://wiki.mikrotik.com/wiki/Dmitry_on_firewalling to test a firewall

But when i added new services to the mangle on the protocol classifier for openvpn, but the connections were marked as other-services as if the new classifier never existed, and got droped at the filter rule restrict-udp.

the case is openvpn connection from workstation to the internet.

the only change i made was i used nat masquerade instead of the transparent proxy.

i wonder if the order of the classifier’s is important and\or the masquerade makes the diference ?


thanks in advanced.