Question on EoIP: Can not route/firewall outside connected network

Dear Mikrotik friends,

I setup an EoIP tunnel between two CHR. Both endpoints are bridges. It’s working fine. I can ping and transfer between the routers and the networks directly connected to the bridges.

What I can not do is ping or reach a device inside the networks from outside, e.g. internet.
When I torch on the bridge, I can see the ping package coming through the EoIP tunnel into the endpoint bridge. Also sniffing shows correct L2 MAC addresses.
I can mangle theses packages and put marks on them (prerouting).

But I can not see these packages in the firewall rules. Only packages from withing the connected networks appear. No packages coming from outside, e.g.internet.

Any ideas what I make wrong?

Thanks,
dksoft

Maybe your NAT rules are incorrect?