Cestou natu by som nesiel kvoli vykonu .. bud stavovy firewall alebo pripadne by sa to mohlo dat vyriesit cez PBR.
Aha citam ze zakaznik ma pristupovat z netu a nema sa dostat do vasej siete.
1.) potrebujes dst-nat z WAN -> Server co predpokladam ze mas.
2.) stavovy fw ..
Nieco ako
## Povolit RDESK -> LAN pokial su sucastou nejakeho spojenia predtym vytvoreneho
add action=accept chain=forward disabled=no connection-state=related in-interface=ether3 out-interface=ether2
add action=accept chain=forward disabled=no connection-state=established in-interface=ether3 out-interface=ether2
## Zahodime ostatny traffic
add action=drop chain=forward disabled=no in-interface=ether3 out-interface=ether2
L.