ICMP is blocked (unwanted)

hi guys
I dont know why for some reason authored users cannot ping any ip beyond router, it seems that ICMP blocked but I can’t find the culprit in my firewall.


thanks

/ ip firewall 
set input name="input" policy=accept comment="" 
set forward name="forward" policy=accept comment="" 
set output name="output" policy=accept comment="" 
add name="hotspot-temp" policy=none comment="limit unauthorized hotspot clients" 
add name="hotspot" policy=none comment="account authorized hotspot clients" 
/ ip firewall rule forward 
add in-interface=onboard action=jump jump-target=hotspot-temp comment="limit access for \
    unauthorized hotspot clients" disabled=no 
add action=jump jump-target=hotspot comment="account traffic for authorized hotspot clients" \
    disabled=no 
/ ip firewall rule hotspot 
/ ip firewall rule hotspot-temp 
add flow=hs-auth action=return comment="return, if connection is authorized" disabled=no 
add protocol=icmp action=return comment="allow ping requests" disabled=no 
add dst-address=:53 protocol=udp action=return comment="allow dns requests" disabled=no 
add action=reject comment="reject access for unauthorized hotspot clients" disabled=no 
/ ip firewall rule input 
add in-interface=onboard dst-address=:80 protocol=tcp action=jump jump-target=hotspot \
    comment="account traffic from hotspot clients to hotspot servlet" disabled=no 
add in-interface=onboard dst-address=:80 protocol=tcp action=accept comment="accept requests \
    for hotspot servlet" disabled=no 
add in-interface=onboard dst-address=:67 protocol=udp action=accept comment="accept requests \
    for local DHCP server" disabled=no 
add in-interface=onboard action=jump jump-target=hotspot-temp comment="limit access for \
    unauthorized hotspot clients" disabled=no 
/ ip firewall rule output 
add src-address=:80 out-interface=onboard protocol=tcp action=jump jump-target=hotspot \
    comment="account traffic from hotspot servlet to hotspot clients" disabled=no 
/ ip firewall service-port 
set ftp ports=21 disabled=no 
set pptp disabled=no 
set gre disabled=no 
set h323 disabled=yes 
set mms disabled=no 
set irc ports=6667 disabled=no 
set quake3 disabled=no 
set tftp ports=69 disabled=no 
/ ip firewall mangle 
/ ip firewall src-nat 
add src-address=192.168.1.0/32 dst-address=:!80 out-interface=ether2 protocol=tcp flow=hs-auth \
    action=masquerade comment="" disabled=no 
/ ip firewall dst-nat 
add dst-address=:53 protocol=udp action=redirect comment="intercept all DNS requests" \
    disabled=no 
add in-interface=onboard protocol=tcp flow=!hs-auth action=redirect to-dst-port=80 \
    comment="redirect unauthorized hotspot clients to hotspot service" disabled=no 
add in-interface=onboard dst-address=:80 protocol=tcp action=redirect to-dst-port=3128 \
    comment="transparent HTTP proxy for hotspot clients" disabled=no 
add dst-address=192.168.0.1/32:4600-4700 flow=hs-auth action=nat to-dst-address=192.168.1.101 \
    comment="" disabled=yes 
/ ip firewall connection tracking 
set enabled=yes tcp-syn-sent-timeout=2m tcp-syn-received-timeout=1m tcp-established-timeout=5d \
    tcp-fin-wait-timeout=2m tcp-close-wait-timeout=1m tcp-last-ack-timeout=30s \
    tcp-time-wait-timeout=2m tcp-close-timeout=10s udp-timeout=30s udp-stream-timeout=3m \
    icmp-timeout=30s generic-timeout=10m