hAP AC2 issue

Hi everyone.
So long story short, there was a default FW rule “drop if not from LAN” which when I enabled, I lost ssh&winbox access to the router, which is strange, because the interface was in LAN interface list.
So, by default first I try to reset the config by holding the reset button until green led is constant then release, for automatic config reset. Waited 10 minutes, not working.
Then I try to reinstall via Netinstall, but the router is now showing up in Netinstall (It’s not the first time I do it, tried it on 2 different PCs, no luck).
I’m not pretty sure if I configured “set protected-routerboot=enabled” on the router and If I did, did I even set the min and max timers.
Now, when I connect PC to any port of the router I get APIPA 169.254.X.X. So if I had set up “set protected-routerboot=enabled” on the router, the config should not have been erased, right?
Because before I reset the device by holding the reset button and going into Netinstall mode I could get IP from the ethernet ports (except port1, normally because it’s for WAN).
Any particular LED lights pattern that shows if the “set protected-routerboot=enabled” is set on the router?
I have the license backed-up, I have the admin user and the password for it, I have the config backed up before router went out. It’s still under warranty, but it’s to far to bring it back from where I bought it, also I had the opportunity to be one of those not desired costumers, not by my fault.
Any chance to bring this device back online, or it’s completely bricked?
BTW, when I connect telecom router into WAN port, then when I connect pc to any of the LAN ports on the Mikrotik, I get IP from the telecom router subnet and I can browse the internet.
Thanks for any suggestions.

For netinstall - check out para H.https://forum.mikrotik.com/viewtopic.php?t=182373

For smoother less error prone config experience, take one port off the bridge and configure from there → https://forum.mikrotik.com/viewtopic.php?t=181718

Hey anav, thanks for taking the time to give some hints. It was somehow stuck in CAPS mode, I was able to solve it via cAP lite and /tool mac-telnet. Thanks again for what you’re doing for the community.

Hello, please tell me how you managed to solve the problem? I have a similar problem and I cannot fix this problem using the officially proposed solutions

I replied to your other thread. Netinstall should not be necessary in your case.