n tenho certeza mas acho q vc fez errado, vou fazer aqui e ver se funciona
\ip firewall filter
add chain=forward src-address=192.168.1.2-192.168.1.9 protocol=tcp dst-port=0-65535 action=drop
add chain=forward src-address=192.168.1.12-192.168.1.254 protocol=tcp dst-port=0-65535 action=drop
add chain=forward src-address=192.168.1.10-192.168.1.11 protocol=tcp dst-port=0-65535 action=accept
flw