Secure MT from Internet and local network

I am wondering if someone has a config recommendation I can use to secure my MT boxes from malicious user inside and outside my network. Currently I have my MT box behind a Dlink 804HV NAT firewall and need to remove, so I can have a public IP subnet presented to the MT box.
My users are currently using private IP’s but some need publix IP’s for various services.


Rgds
M

there is a good example in
http://www.mikrotik.com/docs/ros/2.8/ip/firewall.content
in the example section, starting with “To protect the router from unauthorized access,…”

bye.
matthias