I cann't use ftp server on router from outside after change default ftp port

Well that is just the way MT works. I have a bunch of such rules for every open port or portscan attempt. One solution would be to change default ftp port and create port scan detection rules. So the scriptkiddies cant enumerate your ports so they would fly blind.

Set them up like this
http://blog.codexploit.si/2015/01/mikrotik-port-scanning-firewall-rules.html?m=1

And put them above all other rules. That should stop the bad guys from enumerating your ports. You can test them out with nmap or some other port scan software. Just remember to disable the drop rule while testing.

Sent from my LG-H960 using Tapatalk