here are my input chain firewall rules:
x.x.x.x is my public adress of ruter
192.168.1.2 is my local web server
10.5.50.1 is my hotspot gateway
[slobo@Kula1] ip firewall rule input> print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; winbox from web #1
dst-address=x.x.x.x/32:8081 protocol=tcp action=accept log=yes
1 ;;; winbox from web #2
dst-address=x.x.x.x/32:3986 protocol=tcp action=accept log=yes
2 ;;; emule #1
in-interface=web dst-address=x.x.x.x/32:4662 protocol=tcp
action=accept
3 ;;; emule #2
src-address=10.5.50.0/24 dst-address=:4662 protocol=tcp action=accept
4 ;;; emule #3a
dst-address=x.x.x.x/32:4672 protocol=udp action=accept
5 ;;; emule #3b
src-address=10.5.50.0/24 dst-address=:4672 protocol=udp action=accept
6 ;;; emule #4
src-address=10.5.50.0/24 dst-address=:4661 protocol=tcp action=accept
7 ;;; emule #5
src-address=10.5.50.0/24 dst-address=:4665 protocol=tcp action=accept
8 src-address=192.168.1.0/24 dst-address=10.5.50.0/24 action=accept
9 src-address=10.5.50.0/24 dst-address=192.168.1.0/24 action=accept
10 in-interface=web dst-address=x.x.x.x/32:22 protocol=tcp
action=accept
11 ;;; account traffic from hotspot clients to hotspot servlet
in-interface=wlan1 dst-address=:80 protocol=tcp action=jump
jump-target=hotspot
12 ;;; accept requests for hotspot servlet
in-interface=wlan1 dst-address=:80 protocol=tcp action=accept
13 ;;; accept requests for local DHCP server
in-interface=wlan1 dst-address=:67 protocol=udp action=accept
14 ;;; limit access for unauthorized hotspot clients
in-interface=wlan1 action=jump jump-target=hotspot-temp
15 ;;; Allow established TCP connections
protocol=tcp connection-state=established action=accept
16 ;;; Allow related TCP connections
protocol=tcp connection-state=related action=accept
17 ;;; Allow UDP
protocol=udp action=accept
18 ;;; Allow ICMP Ping
protocol=icmp action=accept
19 ;;; Allow OSPF
protocol=ospf action=accept
20 ;;; Allow access from our local network. Edit this!
src-address=10.5.50.0/24 action=accept
21 ;;; This is web proxy service for our customers. Edit this!
src-address=10.5.50.0/24 dst-address=:8080 protocol=tcp action=accept
22 ;;; Log and drop everything else
action=drop log=yes
any ideas?