На bridge тоже пробовал - толку 0, роутер пингуется, дальше на x.y.203.173 трафик не идет.
[admin@MikroTik] > /ip firewall nat print
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; defconf: masquerade
chain=srcnat action=masquerade to-addresses=x.y.203.174 src-address=192.168.1.0/24 out-interface-list=WAN log=no log-prefix="" ipsec-policy=out,none
1 chain=dstnat action=netmap to-addresses=192.168.1.21 to-ports=80 protocol=tcp dst-port=4480 log=no log-prefix=""
2 chain=dstnat action=netmap to-addresses=192.168.1.22 to-ports=80 protocol=tcp dst-port=5580 log=no log-prefix=""
3 chain=dstnat action=netmap to-addresses=192.168.1.39 to-ports=8080 protocol=tcp dst-port=8989 log=no log-prefix=""
4 X chain=dstnat action=netmap to-addresses=192.168.1.27 to-ports=22 protocol=tcp dst-port=2022 log=no log-prefix=""
[admin@MikroTik] > /ip route print
Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 A S 0.0.0.0/0 ether1 1
1 A S 0.0.0.0/0 x.y.203.173 1
2 ADC x.y.203.172/30 x.y.203.174 ether1 0
3 ADC xx.yy.178.112/29 xx.yy.178.113 bridge 0
4 A S xx.yy.178.113/32 ether3 1
5 ADC 192.168.1.0/24 192.168.1.1 bridge 0