RDP not working in lan

Hello everyone!

Not long ago I bought myself mikrotik hap ax3. I bought it to replace my old Apple Airport 2nd gen. Everything is fine except one thing.

I have a scenario, when i need to connect to my notebook via rdp in local network from my PC. I can’t archive this one because rdp connection couldn’t be established. If I trying to connect from notebook to PC - everything works fine, but it’s not my case - I need to connect from PC to notebook.

I made dhcp reservation for my PC (192.168.24.2) and for my notebook (192.168.24.100). In previous router that was more than enough for correct work RDP in local network.
I also made some firewall settings, but RDP connection not established with or without this settings.
Even more - RDP connection not established when I reset my mikrotik on default configuration.

Can anyone tell me what did I miss?

Here is my config:

# 2023-12-01 11:25:21 by RouterOS 7.12.1
# model = C52iG-5HaxD2HaxD
/interface bridge
add admin-mac=48:A9:8A:6E:57:9D auto-mac=no comment=defconf name=bridge
/interface ethernet
set [ find default-name=ether1 ] mac-address=DC:9B:9C:EF:97:C7
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wifiwave2 security
add authentication-types=wpa2-psk,wpa3-psk disabled=no management-protection=\
    allowed name=wifi-default
add disabled=no name=Dummy
/interface wifiwave2
set [ find default-name=wifi2 ] channel.band=2ghz-ax .frequency=2437-2446 \
    .skip-dfs-channels=10min-cac .width=20mhz configuration.mode=ap .ssid=\
    WifiFree disabled=no name="wifi 2.4" security=wifi-default \
    security.authentication-types=wpa2-psk,wpa3-psk
set [ find default-name=wifi1 ] channel.band=5ghz-ax .skip-dfs-channels=\
    10min-cac .width=20/40/80mhz configuration.country=Russia .mode=ap .ssid=\
    WifiFree5 disabled=no name="wifi 5" security=wifi-default \
    security.authentication-types=wpa2-psk,wpa3-psk
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
add name=dhcp ranges=192.168.24.2-192.168.24.254
/ip dhcp-server
add address-pool=dhcp interface=bridge lease-time=3d name=dhcp1
/port
set 0 name=serial0
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface="wifi 5"
add bridge=bridge comment=defconf interface="wifi 2.4"
/ip neighbor discovery-settings
set discover-interface-list=LAN
/ipv6 settings
set max-neighbor-entries=15360
/interface detect-internet
set detect-interface-list=all
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/ip address
add address=192.168.24.1/24 comment=defconf interface=bridge network=\
    192.168.24.0
/ip arp
add address=192.168.24.2 interface=bridge mac-address=00:D8:61:2F:D4:11
/ip dhcp-client
add comment=defconf interface=ether1
/ip dhcp-server lease
add address=192.168.24.2 mac-address=00:D8:61:2F:D4:11 server=dhcp1
add address=192.168.24.100 client-id=1:f0:77:c3:4d:be:4e mac-address=\
    F0:77:C3:4D:BE:4E server=dhcp1
/ip dhcp-server network
add address=192.168.24.0/24 comment=defconf dns-server=192.168.24.1 gateway=\
    192.168.24.1
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.24.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=drop chain=input comment="Drop - port scanners" src-address-list=\
    Port-Scanners
add action=drop chain=forward comment="Drop - port scanners" \
    src-address-list=Port-Scanners
add action=add-src-to-address-list address-list=Port-Scanners \
    address-list-timeout=2w chain=input comment="Scan - Scan Ports" protocol=\
    tcp psd=21,3s,3,1
add action=add-src-to-address-list address-list=Port-Scanners \
    address-list-timeout=2w chain=input comment=\
    "Scan - NMAP FIN Stealth scan" protocol=tcp tcp-flags=\
    fin,!syn,!rst,!psh,!ack,!urg
add action=add-src-to-address-list address-list=Port-Scanners \
    address-list-timeout=2w chain=input comment="Scan - SYN/FIN scan" \
    protocol=tcp tcp-flags=fin,syn
add action=add-src-to-address-list address-list=Port-Scanners \
    address-list-timeout=2w chain=input comment="Scan - SYN/RST scan" \
    protocol=tcp tcp-flags=syn,rst
add action=add-src-to-address-list address-list=Port-Scanners \
    address-list-timeout=2w chain=input comment="Scan - FIN/PSH/URG scan" \
    protocol=tcp tcp-flags=fin,psh,urg,!syn,!rst,!ack
add action=add-src-to-address-list address-list=Port-Scanners \
    address-list-timeout=2w chain=input comment="Scan - ALL/ALL scan" \
    protocol=tcp tcp-flags=fin,syn,rst,psh,ack,urg
add action=add-src-to-address-list address-list=Port-Scanners \
    address-list-timeout=2w chain=input comment="Scan - NMAP NULL scan" \
    protocol=tcp tcp-flags=!fin,!syn,!rst,!psh,!ack,!urg
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
/ip firewall mangle
add action=add-src-to-address-list address-list=rdp_drop \
    address-list-timeout=1h30m chain=forward comment=\
    "RDP - drop brutforce - go to rdp_drop for 90 minutes" connection-state=\
    new dst-port=3389 in-interface=ether1 protocol=tcp src-address-list=\
    rdp_stage3
add action=add-src-to-address-list address-list=rdp_stage3 \
    address-list-timeout=1m chain=forward comment=\
    "RDP - drop brutforce - 3 attempt" connection-state=new dst-port=3389 \
    in-interface=ether1 protocol=tcp src-address-list=rdp_stage2
add action=add-src-to-address-list address-list=rdp_stage2 \
    address-list-timeout=1m chain=forward comment=\
    "RDP - drop brutforce - 2 attempt" connection-state=new dst-port=3389 \
    in-interface=ether1 protocol=tcp src-address-list=rdp_stage1
add action=add-src-to-address-list address-list=rdp_stage1 \
    address-list-timeout=1m chain=forward comment=\
    "RDP - drop brutforce - 1 attempt" connection-state=new dst-port=3389 \
    in-interface=ether1 protocol=tcp
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
    ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment="RDP to Main computer" dst-port=3389 \
    in-interface=ether1 protocol=tcp to-addresses=192.168.24.2 to-ports=3389
add action=dst-nat chain=dstnat comment=WOL dst-port=42945 in-interface=\
    ether1 protocol=udp to-addresses=192.168.24.2 to-ports=7
add action=dst-nat chain=dstnat comment="bridge rpd" disabled=yes dst-port=\
    3389 in-interface=all-wireless protocol=tcp to-addresses=192.168.24.2 \
    to-ports=3389
add action=masquerade chain=srcnat disabled=yes protocol=tcp src-address=\
    192.168.24.2 src-port=3389 to-ports=3389
/ip firewall raw
add action=drop chain=prerouting comment="RDP - drop brutforce connections" \
    dst-port=3389 in-interface=ether1 protocol=tcp src-address-list=rdp_drop
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=\
    icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" port=\
    33434-33534 protocol=udp
add action=accept chain=input comment=\
    "defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=\
    udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 \
    protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=\
    ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=\
    ipsec-esp
add action=accept chain=input comment=\
    "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment=\
    "defconf: drop everything else not coming from LAN" in-interface-list=\
    !LAN
add action=accept chain=forward comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment=\
    "defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" \
    hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=\
    icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=\
    500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=\
    ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=\
    ipsec-esp
add action=accept chain=forward comment=\
    "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment=\
    "defconf: drop everything else not coming from LAN" in-interface-list=\
    !LAN
/system clock
set time-zone-name=Europe/Moscow
/system note
set show-at-login=no
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool mac-server ping
set enabled=no
/tool sniffer
set file-limit=10000KiB memory-limit=1000KiB

As all interfaces are on the same bridge, from a computer perspective this connection is through a switch (so no firewall involved).
DHCP reservations are beneficial for the IP addresses but not necessary.

I would expect to find the solution in the notebook, is this network a so called “private” or “public” network?
Do you have the option to replace the MikroTik for the Apple device temporarely to check if that is either working or not?

Not sure what you’re trying to achieve with all those port_scanner rules ?
Waste of time, if you ask me. Drop everything, simply add accept rules before that drop rule (don’t forget winbox, webfig,… whatever you need for yourself. And use SAFE MODE or isolate a port, off bridge). No need to spend more cpu cycles on it.

Anyhow…
I would add an explicit accept rule in forward chain for port 3389 and move that before any drop rule in forward chain.
See what happens then.

Advise:
I would group your rules together.
Input with input
Forward with forward
Makes it more clear.

EDIT: after response from erlinden:
Do check firewall on that notebook. Default Windows is pretty consistent in blocking incoming connections.

Hello everyone! Thanks for replies and sorry for long answer.

Long story short - none of your advices helped to me

I switched type of my network on public or private - connection was not established

I checked firewall rules - firewall has allow rules for RDP
I also make this change on mikrotik firewall:

add action=accept chain=forward dst-port=3389 in-interface=bridge protocol=\
    tcp

None if this helped. Once again - I note that on my old apple router rdp on lan works correctly

Are the added rules showing increase in counters ?
If not, they are not doing anything.

And then your issue is on another port or elsewhere.

Yes, counters increasing while I attempt to connect from PC to laptop

Please post the output of the following commands on the notebook

netsh advfirewall firewall show rule name=all
netstat -an

Your post is confusing.
Are you trying to RDP from a remote location into your desktop?
If so stop right there, RDP is not a secure protocol, use Wireguard instead.

If I am wrong and its RDP within the LAN network of the MT, as noted by others, nothing is blocking that.
Your mangle rules are suspect to me and I would remove them for testing purposes.