thanks sindy !
Issue was on Juniper. ISP confirmed that minor issues was on it and now all resolved.
No, I ping google DNS it hosted externallywant lan client to access internet ip service which host on lan VM?
you should use Hairpin NAT by masquerade action to change lan to lan packets.
see https://help.mikrotik.com/docs/display/ROS/NAT, Hairpin NAT.