тебе нужно 2 правила в фильтре:
chain=input action=drop connection-state=!established,related in-interface-list=WAN log=no log-prefix=""
chain=forward action=drop connection-state=!established,related connection-nat-state=!dstnat in-interface-list=WAN log=no log-prefix=""
и 2 правила в NAT:
chain=srcnat action=masquerade out-interface-list=WAN log=no log-prefix=""
chain=dstnat action=dst-nat to-addresses=
192.168.1.103 to-ports=3389 in-interface-list=WAN log=yes log-prefix=""
ip и порт поменяй на свои