/ip firewall filter
add chain=input action=accept protocol=udp port=1701,500,4500
add chain=input action=accept protocol=ipsec-esp
add chain=forward action=accept src-address=
192.168.188.0/24 in-interface=!ether1 out-interface=bridge comment="allow vpn to lan" log=no log-prefix=""