Winbox Access while using mangle rules for x2 PPPoE connections?

Does anyone have any idea why external to the LAN using either public IP, I cannot WinBox (3.17) onto a CCR 1009 using a specified port?

Same port, using external IP works fine when actually connected to the LAN.

Also PPPoE users can no longer access web. Obviously a rule. What am I missing?

Thanks guys,

Steven