Thanks very much for your reply. With your help, my new RB5009 is now working. The key was "you don't have any NAT rule, you need to masquerade in srcnat chain with out.interface ether1." That is, of course, covered in the First Time Configuration wiki article, but evidently I didn't read ...