/ip firewall nat add action=accept chain=pre-hotspot disabled=no dst-address-type=!local hotspot=auth