Dame un export. Si el AP está en modo AP y no router, o es cosa de que está mal hecha la apertura o es cosa del F680
Ese último equipo, el F680, ¿cómo lo tienes? ¿Estás abriendo ahí los mismos puertos a la IP del Mikrotik o lo tienes en DMZ?
Saludos!
El F680 lo tengo en el modo Bridge descrito en este foro, de manera que al no ser un bridge real, más bien un apaño, espero que no esté fastidiando.
En el desplegable IN-INTERFACE qué debo elegir? Todos los puertos Ethernet?
Te paso la configuración:
# apr/03/2021 18:37:51 by RouterOS 6.48.1
# software id = 3ZL9-6G19
#
# model = RBD52G-5HacD2HnD
# serial number = XXXXXXXXXXX
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat dst-port=4662 in-interface=all-ethernet protocol=tcp to-addresses=192.168.2.251 to-ports=4662
add action=dst-nat chain=dstnat dst-port=4672 in-interface=all-ethernet protocol=udp src-address-list="" to-addresses=192.168.2.251 to-ports=4672