/ip firewall layer7-protocol
add name=facebook regexp="^.+(facebook.com).*\$"
add name=youtube regexp="^.+(youtube.com).*\$"
add name=spotify regexp="^.+(spotify.com).*\$"
/ip firewall filter
add action=accept chain=input protocol=icmp
add action=accept chain=input connection-state=established,related
add action=accept chain=input in-interface=ether2
add action=accept chain=input dst-port=1723 in-interface=ether1 protocol=tcp
add action=accept chain=input dst-address=xxx src-address=xxx
add action=accept chain=input dst-address=xxx src-address=xxx
add action=drop chain=input
add action=accept chain=forward connection-state=established,related
add action=drop chain=forward layer7-protocol=facebook src-address=192.168.0.0/24
add action=drop chain=forward layer7-protocol=youtube src-address=192.168.0.0/24
add action=drop chain=forward layer7-protocol=spotify src-address=192.168.0.0/24
add action=accept chain=forward dst-port=80 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx src-address=192.168.0.0/24
add action=accept chain=forward dst-port=5060 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-port=443 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx dst-port=25 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx dst-port=25 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx dst-port=25 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx dst-port=587 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx dst-port=25 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx dst-port=25 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-port=110 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=xxx dst-port=110 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-port=143 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-port=993 protocol=tcp src-address=192.168.0.0/24
add action=accept chain=forward dst-port=53 protocol=udp src-address=192.168.0.0/24
add action=accept chain=forward dst-port=123 protocol=udp src-address=192.168.0.0/24
add action=accept chain=forward dst-address=192.168.0.111 dst-port=22 protocol=tcp src-address=xxx
add action=accept chain=forward disabled=yes dst-address=192.168.0.111 dst-port=22 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=1352 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=3389 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=3389 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=3389 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=1352 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=1352 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=1352 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.112 dst-port=1352 protocol=tcp src-address=xxx
add action=accept chain=forward dst-address=192.168.0.223 dst-port=3389 protocol=tcp
add action=accept chain=forward dst-address=192.168.0.223 dst-port=8080 protocol=tcp
add action=accept chain=forward dst-address=192.168.0.223 dst-port=2700-2710 protocol=tcp
add action=accept chain=forward dst-address=192.168.0.223 dst-port=19701 protocol=tcp
add action=accept chain=forward dst-address=192.168.0.223 dst-port=9877 protocol=tcp
add action=accept chain=forward dst-address=192.168.0.128 dst-port=3389 protocol=tcp
add action=accept chain=forward dst-address=192.168.0.148 dst-port=3389 protocol=tcp
add action=accept chain=forward dst-address=192.168.0.21 dst-port=3389 protocol=tcp
add action=accept chain=forward src-address=192.168.0.249
add action=accept chain=forward dst-address=192.168.0.249
add action=drop chain=forward connection-state=invalid
add action=drop chain=forward in-interface=ether1
add action=drop chain=forward in-interface=ether2
add action=accept chain=output
/ip firewall nat
add action=masquerade chain=srcnat out-interface=ether1
add action=dst-nat chain=dstnat dst-address=xxx dst-port=524 protocol=tcp src-address=xxx to-addresses=192.168.0.111 to-ports=22
add action=dst-nat chain=dstnat dst-address=xxx dst-port=524 protocol=tcp src-address=xxx to-addresses=192.168.0.111 to-ports=22
add action=dst-nat chain=dstnat dst-address=xxx dst-port=522 protocol=tcp src-address=xxx to-addresses=192.168.0.254 to-ports=22
add action=dst-nat chain=dstnat dst-address=xxx dst-port=522 protocol=tcp src-address=xxx to-addresses=192.168.0.254 to-ports=22
add action=dst-nat chain=dstnat disabled=yes dst-address=xxx dst-port=3142 protocol=tcp to-addresses=192.168.0.112 to-ports=3389
add action=dst-nat chain=dstnat dst-address=xxx dst-port=3142 protocol=tcp src-address=xxx to-addresses=192.168.0.112 to-ports=3389
add action=dst-nat chain=dstnat dst-address=xxx dst-port=3142 protocol=tcp src-address=xxx to-addresses=192.168.0.112 to-ports=3389
add action=dst-nat chain=dstnat dst-address=xxx dst-port=3142 protocol=tcp src-address=xxx to-addresses=192.168.0.112 to-ports=3389
add action=dst-nat chain=dstnat dst-address=xxx dst-port=1352 protocol=tcp src-address=xxx to-addresses=192.168.0.112 to-ports=1352
add action=dst-nat chain=dstnat dst-address=xxx dst-port=1352 protocol=tcp src-address=xxx to-addresses=192.168.0.112 to-ports=1352
add action=dst-nat chain=dstnat dst-address=xxx dst-port=1352 protocol=tcp src-address=xxx to-addresses=192.168.0.112 to-ports=1352
add action=dst-nat chain=dstnat dst-address=xxx dst-port=1352 protocol=tcp src-address=xxx to-addresses=192.168.0.112 to-ports=1352
add action=dst-nat chain=dstnat disabled=yes dst-address=xxx dst-port=3392 protocol=tcp to-addresses=192.168.0.223 to-ports=3389
add action=dst-nat chain=dstnat dst-address=xxx dst-port=8080 protocol=tcp to-addresses=192.168.0.223 to-ports=8080
add action=dst-nat chain=dstnat dst-address=xxx dst-port=2101-2110 protocol=tcp to-addresses=192.168.0.223 to-ports=2101-2110
add action=dst-nat chain=dstnat dst-address=xxx dst-port=9877 protocol=tcp to-addresses=192.168.0.223 to-ports=9877
add action=dst-nat chain=dstnat disabled=yes dst-address=xxx dst-port=3346 protocol=tcp to-addresses=192.168.0.128 to-ports=3389
add action=dst-nat chain=dstnat disabled=yes dst-address=xxx dst-port=3345 protocol=tcp to-addresses=192.168.0.148 to-ports=3389
add action=dst-nat chain=dstnat disabled=yes dst-address=xxx dst-port=3314 protocol=tcp to-addresses=192.168.0.21 to-ports=3389