Отключил оба правила, разрешающие выше, перезагрузил маршртуизатор для чистоты эксперимента.
[admin@MikroTik] /ip firewall filter> print detail
Flags: X - disabled, I - invalid, D - dynamic
0 X chain=forward action=fasttrack-connection connection-state=established,related
1 X chain=forward action=accept connection-state=established,related,untracked
2 chain=forward action=drop connection-state=invalid
[admin@MikroTik] /ip firewall connection> print detail
Flags: E - expected, S - seen-reply, A - assured, C - confirmed, D - dying, F - fasttrack, s - srcnat, d - dstnat
0 SAC protocol=gre src-address=
10.0.0.6 dst-address=
10.0.0.2 reply-src-address=
10.0.0.2 reply-dst-address=
10.0.0.6 gre-key=0 timeout=2m34s orig-packets=5 orig-bytes=620 orig-fasttrack-packets=0 orig-fasttrack-bytes=0 repl-packets=5 repl-bytes=620 repl-fasttrack-packets=0 repl-fasttrack-bytes=0 orig-rate=0bps repl-rate=0bps
Router#ping
192.168.1.1Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to
192.168.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 3/10/35 ms