I have nothing regarding firewall in logs. Should it be enabled somehow?If logging is activated on the firewall (drop) rule you might get an indication of the cause of not working.
I have created new rule, but it seems it doesnt work. It is on 2nd position (from top).To answer the Wireguard question: you will have to add an accept rule for that port to the "input" filter rules, not put a dst-nat in the NAT rules.
What does it mean "Select random port # on the WAN side?" Any example?Select any random port # on the WAN side and then redirect it to 3389 in DST rule to make bots/scanner life harder
I have already requested my ISP for public IP.That is why you need your own public IP in such situations.
I understand the risk, opening RDP port is for short period of time to test remote connection and to learn port opening, later I will deploy VPN server.You DON'T WANT to open RDP to your server...
What does it mean? Do I need to contact my ISP or where can I forward the port between my router and internet?you need to forward this port on the router between your MTK and internet