From my computer on local LAN :
tracert PUBLICIP
Tracing route to PUBLICIP over a maximum of 30 hops
1 <1 ms <1 ms <1 ms 192.168.0.1 (Microtik)
2 <1 ms <1 ms <1 ms PUBLICIP
Trace complete.
from the microtik router :
[admin@MikroTik] tool> traceroute PublicIP
ADDRESS STATUS
1 PublicIP 1ms 1ms 1ms
[admin@MikroTik] tool>
those are my NAT rules :
chain=dstnat in-interface=INTERNET dst-address=MyPublicIP protocol=tcp
dst-port=25 action=dst-nat to-addresses=LocalMailServer to-ports=25
1 chain=dstnat in-interface=ASA dst-address=WANIP protocol=tcp
dst-port=25 action=dst-nat to-addresses=LocalMailServer to-ports=25
2 chain=dstnat dst-address=MyPublicIP protocol=tcp dst-port=3000
action=dst-nat to-addresses=LocalMailServer to-ports=3000
3 chain=dstnat dst-address=WANIP protocol=tcp dst-port=3000
action=dst-nat to-addresses=LocalMailServer to-ports=3000
4 chain=dstnat in-interface=ASA dst-address=WANIP protocol=tcp
dst-port=110 action=dst-nat to-addresses=LocalMailServer to-ports=110
5 chain=dstnat in-interface=INTERNET dst-address=MyPublicIP protocol=tcp
dst-port=1433 action=dst-nat to-addresses=LocalSQLServer to-ports=1433
6 chain=dstnat in-interface=ASA dst-address=WANIP protocol=tcp
dst-port=1433 action=dst-nat to-addresses=192.168.0.50 to-ports=1433
7 chain=srcnat out-interface=ASA src-address=192.168.0.0/24
action=masquerade
8 chain=srcnat out-interface=INTERNET src-address=192.168.0.0/24
action=masquerade
9 chain=dstnat in-interface=INTERNET dst-address=MyPublicIP protocol=tcp
dst-port=80 action=dst-nat to-addresses=192.168.0.205to-ports=80
10 chain=dstnat in-interface=ASA dst-address=WANIP protocol=tcp
dst-port=80 action=dst-nat to-addresses=192.168.0.205 to-ports=80
11 chain=dstnat in-interface=INTERNET dst-address=MyPublicIP protocol=tcp
dst-port=11111 action=dst-nat to-addresses=192.168.0.50 to-ports=11111
12 chain=dstnat in-interface=ASA dst-address=WANIP protocol=tcp
dst-port=11111 action=dst-nat to-addresses=192.168.0.50 to-ports=11111
13 chain=dstnat in-interface=INTERNET dst-address=MyPublicIP protocol=tcp
dst-port=110 action=dst-nat to-addresses=192.168.0.69 to-ports=110
15 chain=dstnat dst-address=0.0.0.0/0 protocol=tcp dst-port=97 action=dst-nat>
to-addresses=PUBLICIP to-ports=1433
the last is the rule I added based on your suggestions