Firewall config: Allow incoming ports to hotspot zone

For a friend of mine I would need to configure a Mikrotik router for his bed and breakfast.

He’s using Ubiquity Unifi antenna’s in the following scenario:

Mikrotik Router with portal page configured: (hotspot)

internet connection to Mikrotik router on eth5 (dhcp)
Unifi antenna connected to Mikrotik router on eth1 where:
router = 10.0.0.1
unifi antenna = 10.0.0.254
clients= 10.0.0.2-10.0.0.253

Can someone help me how to configure the Mikrotik router so that the antenna can communicate with the Unifi controller which is situated in the Cloud?
We would need ports 8080, 8081, 8443, 8843 and 8880 to be opened only to 10.0.0.254 (unifi antenna)

I’m not sure what chainset I need to use and what action I should assign in the rule.

Thanks in advance!

Regards,
Kev