Unable to reach a hand full of web sites...

I have a 3011UiAS router that for some reason cannot reach a couple of web sites. If I remove the router from the IPS’s modem and connect a laptop directly to the ISP’s modem and use the static IP assigned to the router on the laptop, I can get the those web sites without issue. One would clearly tell me that I have a firewall rule issue in the router but I have no firewall rules, I have removed EVERYTHING, EOIP tunnels, every filter rule, all address lists, all NAT rules, except for the basic NAT masquerade rule, IP addresses (Wan & LAN) and IP routes needed to get to and froe. I made sure that I was using my IPS’s DNS. I can get to 99% of the web site on the planet except for a hand full. Ironically the ones I cannot get to are all in AWS cloud space, not that AWS has anything to do with this issue. I have been working on this for several hours and I am stumped… This router is in a remote location so resetting it requires me to arrange having someone on premise and that someone will a novice computer user so, I am trying to avoid having to reset the router.

I will consider any suggestion you folks could throw my way, thank you.

NOTE: I open the Quick Set interface on this router, which I did NOT use to configure it, as a matter of fact, I never use it and void it like the plague. I have been using RouterOS for 10 years and have never used it. To me it is a novice tool, regardless of my personal opinion; When I open it on my 3011UiAS router it defaults, in the configuration section, to Bridge mode. I am hoping that the Quick Set interface does not understand the settings I have manually created and not because my router is somehow misconfigured! Could anyone shed some light on why it is defaulting to Bridge mode? And could this be related to my issue?

Again thank you in advance.

Depending on ROS version and original FW config it is quite possible that your router got hacked.

Export current config to text file (/export file=config.txt), save that file to your computer. Then netinstall the router (google for exact procedure) and start configuring it from default rules. Depending on device, default FW rules are either decent or non-existing (in the later case you’ll have to get them from elsewhere, I recommend this forum over youtube tutorials). Use exported configuration only as reminder, not as guide!

And do all of it before connecting router back to internet or else you risk getting hacked before you finish configuring it.

Thanks for the reply BR. What you say is quite possible. I have had this 3011 for at least 3 years so it is within the period of time when ROS was vulnerable.
Have a great day!